Some websites have ridiculous security flaws.
Thankfully the public is slowly becoming more aware, and many sites are fixing the more obvious ones, like lack of HTTPS, poor password creation guidelines, and plain text password storage.
But there are still a ton of offenders, and many people don't have someone to correct their behavior.
My question is, are there any sites that exist to expose poor security habits? Something like PTO , but for, say, collecting sensitive information over HTTP?
(I'm asking because I recently encountered a small company's website that collected payment info over HTTP, and wrote them a rather long-winded email about the possible dangers of the practice, and about solutions they could implement free of charge, and was completely ignored.)
Edit:
I am not asking when it's okay, I just want to know if there's a place to do it, or somebody I could contact about it (aside from the site's owner).