web-payments / web-commerce-api

A specification for initiating payments in the browser
7 stars 1 forks source link

Security considerations section #9

Open msporny opened 11 years ago

msporny commented 11 years ago

There is currently no section on security considerations in the specification. There should probably be something containing an analysis of the security implications of the protocol.

kumar303 commented 11 years ago

There were many rounds of security reviews at Mozilla for what is now navigator.mozPay(). Here's some logging of the security reviews but some of the info is outdated by now. A lot of the threat models still apply.