4 ms·
As devs, we know in theory Stripe and PayPal are roughly equivalent in terms of protecting a card number. But the streamlined Stripe UI with the subtle branding
by CodeWriter23 7y ago
As devs, we know in theory Stripe and PayPal are roughly equivalent in terms of protecting a card number. But the streamlined Stripe UI with the subtle branding doesn't drive home to the customer that Stripe is keeping your card number safe vs. random merchant storing all 16 digits in a hackable database somewhere.
The friction in the PayPal UI of making you log in to PayPal to make the payment is a pretty big trust signal IMO.
- TazeTSchnitzel 7y agoStripe isn't as safe. PayPal collects my details only on paypal.com, Stripe collects my details on all sorts of domains, where who-knows-what JS might be present.
- CodeWriter23 7y agoAre you speaking about real threats that cannot be mitigated by best practices, or theoretical threats of the future? I guess in other words, I’m under the impression using Stripe and following OWASP and script signing that my customers are safe. If I’m incorrect please pass me a clue.
- kalleboo 7y agoAs a customer, how do I verify that the merchant is following best practices and hasn't by mistake forgotten some ad script enabled on the payment page? With PayPal as long as I only enter my password on paypal dot com I know I'm safe.
- CodeWriter23 7y agoIf you’re very careful and copy/paste the PayPal URL into an editor and verify you didn’t get sent to PayPal.com.evil.domain, then you’re very likely to be safe.
- TazeTSchnitzel 7y agoI don't need to do that, browsers carefully show the actual domain in ways to avoid that problem since a few years now.