Event photographer website booking and registration via insecure connection
What is the problem?
This website’s Terms state that “You are entirely responsible for maintaining the confidentiality of you(sic) password and nickname” and “You agree to notify JerseyVIP.co.uk immediately of any unauthorized use of your account or any other breach of security.”
These Terms make no sense as website login security is the sole responsibility of the webmaster, and users have no control over this factor, except to refuse to use the site.
Prior to public disclosure, notification about any privacy or security issues discovered were sent by email to the operator of this website on 22nd August 2018, using either an email address publicly discoverable on the site, or the RFC 2142 standards compliant address "webmaster@..." if no public email address was provided.
At time of posting the issue had not yet been resolved.