Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Surely that's a bad thing? It would be trivial to make an identical Javascript popup which harvested data rather than sending it off to Stripe. Yes, the current redirect-ad-infinitum workflow is reasonably trash, but this scares me a lot, and I'd personally not trust it.


I think the idea would be that this is in a https payment page of the client company who you would then choose to trust (or not) as implementing the payment frame correctly. Just like if they had their own payment solution essentially.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: