Re: [w3c/payment-handler] Open Window Algorithm and tracking through 1ps (#351)

> If I read the spec correctly, the standard would allow the payment processor to track the user across pages that use the processor, since the processor would always have access to the same global storage, instead of different storage for each 1p it appears under

A payment processor accumulates information about merchants and users anyway.

Vetting is (IMO) the only way forward because a compromise will most likely leave everybody unhappy. Adding a set of "consents" which 99% of the user base do not understand the consequences of seems like a repeat of the pretty failed cookie consent thing.

FWIW, vetted native payment handlers like Apple Pay and [Saturn](https://cyberphone.github.io/doc/saturn/) are also _domain agnostic_ which give them a clear edge over `PaymentHandler`.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/payment-handler/issues/351#issuecomment-610778390

Received on Wednesday, 8 April 2020 06:35:46 UTC