Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why would the merchant site need to sniff anything? Once a customer has made any purchase, the merchant then has direct access to charge their cards from the Stripe dashboard. That's why it is a huge responsibility to use these services.

Unless it is something that I've misunderstood?



Yes, that's another problem with Stripe. PayPal also requires you to verify the charge in their UI, with the amount shown.

But a Stripe token (as implemented correctly) is still not quite as powerful as the card info itself, since it can only be reused with Stripe by that merchant.


Thank you for clarifying.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: