4 ms·
Most websites can't/shouldn't store the card number, they embed Stripe JavaScript that sends card number to Stripe and get a token id to use on the backend late
by justinholmes 6y ago
Most websites can't/shouldn't store the card number, they embed Stripe JavaScript that sends card number to Stripe and get a token id to use on the backend later on.
Can't store CCV or number without passing PCI compliance.
- tzs 6y agoFor the CVV you can't store it even if you have passed PCI compliance. You are only allowed to collect it for a specific transaction, and are required to forget it when that transaction is complete.
- 8192kjshad09- 6y agoThat can't be right. I entered my credit card information once into uber eats and I can buy food whenever without entering a CCV and my credit card is immediately charged. If this were true 1000s of large companies would not be PCI compliant.
- athrun 6y agoStoring the CVV permanently is indeed strictly forbidden. The CVV is not used for purchases on a stored card.
- deleted 6y ago[deleted]
- JoeMalt 6y agoIt’s possible to process transactions without a CVV, but it often costs slightly more due to the increased fraud risk. In the case of Uber Eats, they’ve presumably decided the increase in purchases from removing that friction makes up for the higher fee.
- adrianmonk 6y agoInteresting. Do they literally embed Stripe JS? I'm not a front end developer and don't know a ton about web security, but it seems like a malicious/hacked site could still get the card number this way. The purpose of PCI compliance is to protect the number/info, so how would Stripe (and similar) get approved if they're creating a payment widget that allows third parties to snoop card numbers? Is this a PCI loophole, or is there some technical barrier preventing the third-party site from getting access?
- realmod 6y agoStripe JS uses an iframe for card number which blocks the site from accessing the number. And the only way to access the card number is either a security hole in the iframe message handling or in the browser.
- adrianmonk 6y agoThanks, that makes sense. It's <iframe>, not <script>. (They're embedding more than JS.)
- gruez 6y agoNot really. It's true that the main site (parent of the iframe) wouldn't normally have access to the card numbers, but there's nothing preventing you from replacing the iframe entirely. There isn't an "address bar" for iframes, and people certainty aren't manually checking the address by right-clicking, so there's a very high chance you can get away with it. Even if some user checked and noticed the iframe was missing, there are enough sites that don't use iframes for payment processing (ie. they submit credit card numbers directly to their servers) that it wouldn't look out of place.
- realmod 6y agoYeah that is true. I guess in the end you still have to trust the site unless it uses the stripe hosted checkout.
- adrianmonk 6y ago> There isn't an "address bar" for iframes Maybe there should be? If it's important to know what site you're looking at in a top level page, the same thing should apply to an embedded one. Often when I learn about web security, it seems like the user agent abdicates responsibility to be an agent for the user. Probably a case where it's more obvious in hindsight why this is important, but it could still be retrofitted. Maybe there's a better way, but for example, a browser could make the address bar a breadcrumb widget using multiple URLs to depict the iframe nesting.