Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8394387
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 9, 20262026-06-09T20:02:51+00:00 2026-06-09T20:02:51+00:00

Let’s say there is a third party site not protected under https. The third

  • 0

Let’s say there is a third party site not protected under https.

The third party site integrated a javascript call that basically gets a payment form from my site and adds the payment form on the third party site.

The person fills out the payment form which has a form action of “https://example.com/… ” where example.com is my site.

Will their information be encrypted even though they are filling out the payment form on a site not https protected, but the form action is https protected.

so basically:

the site that the payment form gets shown in is called http://thirdparty.com/welcome

The payment form has the following form code:

<form name = "payment" action = "https://example.com/process">

this form is being shown on a non-https encrypted site: http://thirdparty.com/welcome
and being sent to https://example.com/process

will the information provided in that form be encrypted?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-09T20:02:53+00:00Added an answer on June 9, 2026 at 8:02 pm

    The information they submit will be encrypted when it is sent over HTTP…

    … but the page containing the form is insecure, can be intercepted enroute to the client, and can have extra JavaScript added to it. Such JavaScript might copy the payment information they enter to an attacker’s server (before it gets encrypted).

    So the approach is, overall, not secure.

    The user should be directed to a form hosted by your site in a page on your site, and not embedded on a third party site.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Let me explain best with an example. Say you have node class that can
Let me try to explain by example. Say website is hosted at example.com (NOT
Let's say that I have a SQLite database that I create in a separate
Let's say I can call a method like this: core::get() . What is the
Let's assume that we are building a high traffic site that will be used
Let's say there is a graph and some set of functions like: create-node ::
Let's say I have multiple requirements for a password. The first is that the
Let's say that I have a date in R and it's formatted as follows.
Let's say you have a method that expects a numerical value as an argument.
Let's say I have a bunch of links that share a click event: <a

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.