w3c / src

Other
7 stars 7 forks source link

Phishing-resistant #36

Open marcoscaceres opened 4 years ago

marcoscaceres commented 4 years ago

The modal window approach improves security because the browser displays the payment handler origin, making phishing more difficult.

I'm hesitant to have the document say the above... we don't know how much it helps, as I don't know if anyone has user tested this.

ianbjacobs commented 4 years ago

I think it is valuable that (in this implementation) the browser displays the origin. Would you be ok with:

"Because the browser displays the payment handler origin at the top of the modal window, this can help foster user trust in the handler."