4 ms·
> Myself, I'd place a lot of trust on cperciva Sure, but you can just compare the two sites' external measures of security, and they're not even close. Stripe
by semenko 14y ago
> Myself, I'd place a lot of trust on cperciva
Sure, but you can just compare the two sites' external measures of security, and they're not even close.
Stripe domains:
- Pass optional HTTP security headers (like X-Frame-Options on manage.stripe.com)
- Are pinned to Chrome's HSTS list (http://src.chromium.org/viewvc/chrome?view=rev&revision=84125 http://src.chromium.org/viewvc/chrome?view=rev&revision=...) and pass a Strict-Transport-Security header
- tptacek 14y agoAren't you comparing Colin's iframe with a level of security unobtainable to normal Stripe developers? If you just use Stripe's JS interface the way they tell you to, you're not strictly speaking benefiting from Stripe's HSTS or XFO; your site still needs to defend against clickjacking and SSL stripping. I feel like Colin built this little thingy to solve a real problem --- that by adding Stripe to his site, he was giving Stripe control over his site, and his site hosts information more sensitive than credit cards --- and people are piling on because his solution to his little problem doesn't solve every other imaginable security problem. This would be less galling if the kinds of sites using Stripe today weren't almost uniformly rife with application security flaws that defeat most of the good intentions that Stripe has.