[w3c/webpayments-methods-card] Leave Off Unneeded Information (#5)

This is a recommendation from the Security and Privacy Checklist review. See https://docs.google.com/document/d/1w7ginyzNg-xZUmITK4vzcGUKB4gbMOAvlkWWaRtX14k/edit?usp=sharing for additional detail

The Basic Card Payment specification provides additional information that forms a unique correlator. Unlike unique, cross-origin information provided by the Payment Request API, the cardNumber field provided by the Basic Card API is (necessarily) required rather than optional. The current document appears to assume that any Basic Card Payment app will request all possible fields; however, there is [a PR filed for leaving off unneeded information](https://github.com/w3c/webpayments-methods-card/pull/4). For the sake of privacy, we recommend this PR be accepted.

---
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/webpayments-methods-card/issues/5

Received on Wednesday, 10 August 2016 20:05:48 UTC