Hacker News new | ask | show | jobs
by james-singh 4943 days ago
Don't they need to go through PCI-DSS certification? http://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Secu...

I think those who've received the certification are pretty much worth the trust. I don't see anything like that on stripe.com homepage though. Ditto for paymill.com.

1 comments

Sorry, looking back, my response wasn't very clear.

I didn't mean Stripe's backend, but the website owner's. Before passing the data to Stripe's API, the website owner might intentionally or unintentionally do something insecure with your details.

Meaning if you wanted to feel 100% safe with your transaction you may prefer to enter your details on Stripe's website where you trust that company and their implementation of security measures.

Unfortunately, if someone wants to try and trick a user into getting their details, there is an infinite number of ways to make their payment page look secure. Worse still, non-tech people wouldn't know to trust a company like Stripe as opposed to any other made up company.