3 ms·
This post is inaccurate. (Check out Darragh's response in the comments.) It's also worth noting that 1) Stripe and its processes are audited every year (we're a
by pc 13y ago
This post is inaccurate. (Check out Darragh's response in the comments.) It's also worth noting that 1) Stripe and its processes are audited every year (we're a PCI-certified service provider), and 2) that MasterCard has actually followed a very similar strategy with their Stripe competitor.
- patcheudor 13y agoStripe's level one service provider which is independent of the merchants PCI compliance. The merchant is presenting the form for which the user enters their credit card information from within the context (same origin) of their domain: e.g., https://merchant.com/payment.. https://merchant.com/payment... As a result, under the PCI DSS they are obligated to protect that component of the transaction because if they don't a criminal could change it so that the card data doesn't POST to Stripe.com but instead goes to the criminal. Implementing a bit of Javascript and enabling SSL/TLS is far from all that is needed to be PCI compliant as a merchant so long as the payment form itself, whether delivered via an iFrame or a bit of Javascript is hosted within the merchant domain.