[webpayments] How do we prevent keyboard hooking during payment? (#90)

I looked through the architecture part and didn't find anything related. During payment process, when user types his login password or payment password, his environment may be insecure and some hook processes may exist, then these malicious processes can get what users type. So does our proposal contain something related with secure input? And should it be handled by which part? Payment App, Payment Method or Payment Mediator?

