w3c / payment-request

Payment Request API
https://www.w3.org/TR/payment-request/
Other
488 stars 135 forks source link

Document privacy and security mitigations #675

Closed marcoscaceres closed 6 years ago

marcoscaceres commented 6 years ago

As part of the CR process and through implementation/deployment, we've learned quite a bit about abuse cases. We should make sure we properly document all mitigations we've put in place without being hand-wavy - in the Privacy and Security section.

And so on... please add more to the above... those are just the ones off the top of my head.

cc @lknik.

ianbjacobs commented 6 years ago

Hi @marcoscaceres,

Want any help drafting text?

Ian

marcoscaceres commented 6 years ago

Help is always welcomed, @ianbjacobs.

stpeter commented 6 years ago

Both https://www.w3.org/TR/credential-management-1/ and https://www.w3.org/TR/encrypted-media/ have text we could emulate about secure contexts. The latter document especially has thorough sections on privacy and security.

marcoscaceres commented 6 years ago

Merged the ones listed, so closing.