Re: [w3c/payment-handler] Basic-credit security issue (#379)

Hi all,

I wanted to mention some other aspects of mitigation:

* Chrome uses the safe browsing [1] database to help the user avoid installing potentially harmful Web-based payment apps.
* Payment apps (including Web-based) installed "on the fly" require a user gesture before installation.

If we can improve security further, that would be great. I welcome suggestions here. 

Ian

[1] https://safebrowsing.google.com/

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/payment-handler/issues/379#issuecomment-740729968

Received on Tuesday, 8 December 2020 16:20:04 UTC