Re: [w3ctag/design-reviews] Secure Payment Confirmation (#544)

Another thing that may be non-obvious is that SPC signs payment request data.  Unlike many other signature schemes the requester (merchant) and the consumer (bank) are different entities which adds an additional constraint: the data to be signed must be standardized.  Note: this is NOT a problem, this is how payment systems work.  What it does say though, is that there is not a lot of leeway here.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/544#issuecomment-899479315

Received on Monday, 16 August 2021 12:44:08 UTC