Magecart fiends punch card-skimming code in Sotheby's Home website

Turn off javascript

Turn off javascript.

Then, of course, the page stops working. But any web dev that relies on client side scripting on a payments page should be barred permanently from the trade. Nothing sensitive or state-changing should ever be done client side (hence the invention of POST). It needs more expertise to do the job server-side, and that's the whole thing - fundamental lack of expertise in those tasked with mission- and security-critical systems development.

