Re: sketching out HTTP 402 workflow

On 2015-07-26 16:31, Melvin Carvalho wrote:
<snip>

>     Well, I'm just talking about this smallish issue which is providing the
>     initial link, something none of giants in the industry have manged come
>     up with a solution to.  Microsoft once tried but that's about the only
>     serious attempt I have heard about.
>
>
> The initial link can be clicked on.  Or put in the query string.

I'm referring to the link to the payment provider.


Or in local storage.  Or in indexed db. Or found in a certificate.  Or typed into a form.

How does the merchant server know where to go?


> Hopefully the credentials API will give another solution.

The payment industry isn't going to buy into a new password management scheme even if it comes from Google.
AFAICT, there's no interest from the other browser vendors either.


> I think we have enough options to work tho.

The (IMO) only thing that provably works is the "SuperProvider" concept like PayPal.

This topic [presumably] resides at the FIDO alliance which I don't have any insights in.
Even if I had such information I couldn't tell since FIDO require their members signing an NDA!

Anders

Received on Sunday, 26 July 2015 14:50:43 UTC