|
|
|
|
|
by adrianmonk
2125 days ago
|
|
Interesting. Do they literally embed Stripe JS? I'm not a front end developer and don't know a ton about web security, but it seems like a malicious/hacked site could still get the card number this way. The purpose of PCI compliance is to protect the number/info, so how would Stripe (and similar) get approved if they're creating a payment widget that allows third parties to snoop card numbers? Is this a PCI loophole, or is there some technical barrier preventing the third-party site from getting access? |
|