w3c / secure-payment-confirmation

Secure Payment Confirmation (SPC)
https://w3c.github.io/secure-payment-confirmation/
Other
106 stars 48 forks source link

[Spec] Expand 'payment attack' section for on-path attacks #214

Closed stephenmcgruer closed 1 year ago

stephenmcgruer commented 1 year ago

SPC already has mitigations against on-path attacks, where an attacker positions themselves between the user and a valid merchant website. However we did not previously explain how a Relying Party can detect this, so add a line about it.


Preview | Diff

stephenmcgruer commented 1 year ago

(ipr checks currently failing because Google needs to re-join the WPWG post-recharter. Attempting to get that addressed today)