Browsers Will Store Credit Card Details Similar To How They Save Passwords (bleepingcomputer.com)
An anonymous reader quotes a report from Bleeping Computer: A new W3C standard is slowly creeping into current browser implementations, a standard that will simplify the way people make payments online. Called the Payment Request API, this new standard relies on users entering and storing payment card details inside browsers, just like they currently do with passwords. The API is also a godsend for the security and e-commerce industry since it spares store owners from having to store payment card data on their servers. This means less regulation and no more fears that an online store might expose card data when getting hacked. By moving the storage of payment card details in the browser, the responsibility of keeping these details safe is moved to the browser and the user. Browsers that support the Payment Request API include Google Chrome, who first added support for it in Chrome for Android 53 in August 2016, and added desktop support last month with the release of Chrome 61. Microsoft Edge also supports the Payment Request API since September 2016, but the feature requires that users register a Microsoft Wallet account before using it. Firefox and Safari are still working on supporting the API, and so are browser implementations from Facebook and Samsung, both eager to provide a simpler payment mechanism than the one in use today.
With the greatest respect:
How about no.
... just like they currently do with passwords
I don't trust any browser to store even my Slashdot login password. Why in the world would I trust it with my credit card? In fact, I don't even let merchants store my credit card if at all possible (I either choose the option not to save the card or manually delete the card after the purchase).
It seems like nobody who understands and actually values privacy and security would do this.
Does this mean that browsers are going to have to be PCI DSS certified?
That would certainly be interesting, because PCI for example prohibits using anything less than TLS1.2 for secure comms, which might bleed-over into general communications. Could this be the end of non-HTTPS web traffic and SSL/TLS before v1.2? Will browser vendors have to choose between interoperability with (old, shitty) servers and providing storage and transmission of credit card info?
It would be kind of awesome if one DID imply the other, because the internet would get a lot less shitty really quickly.
very long since we have to change numbers pretty often because of fraud. With my Chase card, I think my number changed three times since I got it six years ago. With my Barclays card, I've already changed number three times just this year! Neither card has a chip, so I swipe them at a lot of places. Food trucks seem to be the worst since twice immediately after I bought something from a taco truck, I had charges from FAST STOP 1107 in Texas three different times.
The government has a program in place that you can take advantage of to prevent credit card fraud at high-risk situations like taco trucks. It's a paper certificate called a "Federal Reserve Note", and it's now widely available.
Do you even need to ask that question?
The funz will really start when they extend the APIs to allow for recurring charges, one of the common billing scams - it wont be long I am sure.
'WE JUST NEED TO VERIFY YOUR CCARD WITH A $0.01 CHARGE TO VALIDATE YOU' (tinyprint hidden, we will also start charging you $39.95 per month for an email telling you our monthly lucky numbers, and it is basically impossible to cancel).
So yes, the ONLY valid answer to this if 'NO F'in WAY'
In NO way should ANY browser store Credit Cards!
Why not?
I'd rather have someone steal my credit card info than my slashdot credentials.
I can always cancel (and get a full refund for) any fraudulent CC charges. But a slashdot post under my name is permanent.
Have you ever tried to cancel a payment? It can take many months. During this time you will no doubt have to get a new card/account details, update regular payments and quite likely be without any spending cash for several days. I think the inconvenience factor and being observant enough to catch fraud before you're rendered bankrupt far out weighs potential gain vs risk.
Why UNIX?
Conversion rates in the checkout flow are a key measure for ecommerce sites. 46% of e-commerce shoppers abandon the checkout process during the payment phase, signaling frustration with the complexity and redundancy of re-entering form data or tracking down payment information. Even a small increase in the success rate of checkout make a direct impact on your site’s bottom line, while improving the shopping experience for customers.
From Payment Request API
Many problems related to online purchase abandonment can be traced to checkout forms, which are user-intensive, difficult to use, slow to load and refresh, and require multiple steps to complete.
Sure, this API may make things simpler for you -- the purchaser -- but it seems the focus is on benefiting the seller. Perhaps a narrow distinction, but one that may matter if/when push comes to shove and a side must be chosen by the developers.
Another thing to consider: Since this is implemented in the browser, if you use multiple browsers to shop, then you'll have to store your information in each browser rather than once on the websites on which you shop -- unless the browser vendors can cooperate on a single, shared data storage method.
It must have been something you assimilated. . . .
I read quite a few of the comments, and noticed that people here are well aware of the problems with having a browser store this kind of information. And yet, I have a bad, bad feeling that in a few years, it's going to be ubiquitous, perhaps even compulsory. I'm surprised they actually spelled it out so clearly:
"By moving the storage of payment card details in the browser, the responsibility of keeping these details safe is moved to the browser and the user."
That's it right there. The banks and credit card companies have been trying ever since plastic was invented to make consumers responsible for losses due to fraud and theft. This is their ticket to paradise.
So watch for deep discounts. Watch for a flood of trolls masquerading as coolest-of-the-cool tech lords explaining how everybody who isn't a doddering old fool is using it. Watch for laws drafted to force you to use it. Like when you have to renew your driver's license, you get a choice of waiting in an endless line during business hours at a single tiny government office, or bringing your smart phone and an app to a no-wait kiosk in a mall, or doing it from home...ONLY if you use the browser function. Watch for more and more stores refusing to accept bills larger than $10 for cash transactions "because counterfeit" or "because security".
I'm sure there's a dozen more ways, all based around that "well, nobody's forcing you" lie that's been used so often and so well.
Let's hope that for once people get together and shut this down before it gets started. Right now liability for fraudulent financial transactions is right where it belongs. We need to keep it that way.
I've calculated my velocity with such exquisite precision that I have no idea where I am.