3 ms·
Are you speaking about real threats that cannot be mitigated by best practices, or theoretical threats of the future? I guess in other words, I’m under the impr
by CodeWriter23 7y ago
Are you speaking about real threats that cannot be mitigated by best practices, or theoretical threats of the future? I guess in other words, I’m under the impression using Stripe and following OWASP and script signing that my customers are safe. If I’m incorrect please pass me a clue.
- kalleboo 7y agoAs a customer, how do I verify that the merchant is following best practices and hasn't by mistake forgotten some ad script enabled on the payment page? With PayPal as long as I only enter my password on paypal dot com I know I'm safe.
- CodeWriter23 7y agoIf you’re very careful and copy/paste the PayPal URL into an editor and verify you didn’t get sent to PayPal.com.evil.domain, then you’re very likely to be safe.
- TazeTSchnitzel 7y agoI don't need to do that, browsers carefully show the actual domain in ways to avoid that problem since a few years now.