5 ms·
If somebody who doesn't know what they're doing is writing a CC form, you've already lost. Making app development easier isn't "dangerous" because it allows les
by benaiah 12y ago
If somebody who doesn't know what they're doing is writing a CC form, you've already lost. Making app development easier isn't "dangerous" because it allows less experienced people develop applications. You will always have people making mistakes and screwing up security, regardless of the actual ease of development. The more the developer has to do, the more they can screw up.
- logicallee 12y agoThis is what my point is: as much as the customer has to slow down and say, "Wait a second, is this legit?" - so do we. That doesn't mean the customer won't conclude it is legit, or that we don't conclude the same thing. Recall that I had responded to, >Looks gorgeous. I can't help but wonder if people unfamiliar with technology and ecommerce would be deterred by such a form? Certainly I personally would be deterred (to an extent) from using this form without at least a cursory audit and verifying the identity of the person who wrote it. This will naturally be less and less important the more eyeballs this sees. But as a simple tool, perhaps it is not that many. Do remember that if I were wanting to get my hands on people's credit cards, getting developers to use this kind of script while having a well-hidden side channel (perhaps quite well-hidden - it could somehow encode cc details in the timing delays to a different server, potentially, so that it is not at all obvious that the delays even correspond with the data, it could just look like visualizations getting loaded as the person types) -- then this would be one of the more clever ways I could go about doing so. I don't see how we're 'arguing' about this? We need to check what we are using, just like customers need to check that this is legit.
- benaiah 12y agoI don't really understand your point. The thing about timing channels is absurd - we have the code right in front of us. Right there. It either calls third-party servers or it doesn't, and we can see that. Very easily. The idea that anyone would successfully steal CC info by putting up an open-source client-side jQuery plugin under his real name is just silly. It's not something that you ever have to worry about in the real world. Sure, I'll concede that if a number of absurdly unlikely things happened, something like this could steal CC info. Besides, you're missing the point. We're paid to vet this stuff. Customers aren't. Your choice of whether to use this or not harms no one - but customers being scared of an odd-looking CC form is harmful to business, and a valid and interesting point.
- logicallee 12y agowe're not disagreeing