Thanks for double-checking my work Alex. -----Original Message----- From: Alexander Hawley [mailto:[log in to unmask]] Sent: Tuesday, August 16, 2011 10:01 AM To: [log in to unmask] Subject: Re: [MSUNAG] shop.msu.edu Insecure Confirmed. It definitely posts credit card number in plain text over unencrypted HTTP. Captain Obvious: this is why MSU has a payment processing system.