W3C home > Mailing lists > Public > public-webapps@w3.org > April to June 2012

Re: Browser Payments API proposal

From: Elliott Sprehn <esprehn@gmail.com>
Date: Tue, 19 Jun 2012 11:23:09 -0700
Message-ID: <CAPJYB1hRrfCSoABPuNu=RM3L7mOr_VYwn4LZf+WAqqmaEDaRvA@mail.gmail.com>
To: Yaar Schnitman <yaar@chromium.org>
Cc: Alex MacCaw <maccman@gmail.com>, public-webapps@w3.org
I'm not sure this is a problem worth solving in the platform. In 5-10 years
I doubt we'll be typing our card numbers into pages. You'll tap your phone
to your laptop or use some kind of payment service like paypal/wallet/etc.

There's so many security/privacy issues with exposing your payment
information behind an infobar to any page that requests it.

On Tue, Jun 19, 2012 at 10:15 AM, Yaar Schnitman <yaar@chromium.org> wrote:

> Nice idea Alex!
>
> I have done some work on this in the past, but it didn't go very far. A
> few tips:
> 1. As long as many users don't have this, websites would still have to do
> form-based credit-card forms. But browsers and extensions are getting
> pretty good at auto-filling these forms. So you have a tough competition
> from the entrenched technology and there are ways websites can help the
> auto-complete work even better (e.g. proper element names).
>
> 2. The permissions dialog needs to be more visible and proactive. Users
> (even advanced ones) often miss the permissions prompts.
>
> 3. Requiring the user to type a security code / pin every time you give a
> site your credit card info might increase awareness and security.
>
> 4. Can we do something that doesn't require scripting? Maybe a new tag?
> The motivation for that is embedding one click payments in emails where
> scripting is disabled.
>
> 5. Minor things: How to deal with multiple credit cards? What if a site
> only suports AmEx but not Visa?
>
>
> On Sun, Jun 17, 2012 at 5:34 AM, Arthur Barstow <art.barstow@nokia.com>wrote:
>
>> On 6/16/12 8:16 PM, ext Alex MacCaw wrote:
>>
>>> The blog article link has changed to: http://blog.alexmaccaw.com/**
>>> preview/**Pc1LYBw4xDT95OPWZGihod7z8Whrnf**AdXMjQxMDg3MTc5NDIaXNjA1p<http://blog.alexmaccaw.com/preview/Pc1LYBw4xDT95OPWZGihod7z8WhrnfAdXMjQxMDg3MTc5NDIaXNjA1p>
>>>
>>
>> Alex - perhaps this API will be of interest to the Web Payments Community
>> Group <http://www.w3.org/community/**webpayments/<http://www.w3.org/community/webpayments/>>.
>> -AB
>>
>>
>
Received on Tuesday, 19 June 2012 18:23:58 GMT

This archive was generated by hypermail 2.3.1 : Tuesday, 26 March 2013 18:49:52 GMT