3 ms·
> But if an attacker steals a token, they can make that same API call and charge a card to pay themselves. I can't speak for every payments product but in the
by Merad 5y ago
> But if an attacker steals a token, they can make that same API call and charge a card to pay themselves.
I can't speak for every payments product but in the one I work with tokenized cards are tied to one merchant. A compromised token can only be used to process payments to that merchant.
- leesalminen 5y agoSame here for the many payment processors I’ve worked with in the past. Except for the one time the processor swore up and down that tokens were tied to a merchant when they weren’t. It took several weeks of pestering support with example curl commands to convince them to escalate to someone who knew how to run a curl command. Then the bug was fixed within an hour.