#benflynn

1 messages · Page 1 of 1 (latest)

quiet jacinthBOT
obtuse hound
wanton latch
#

Thanks @obtuse hound . Yeah- we've been using that document, just wanted to make sure we weren't missing some seurity recommendations serving up that token. I appreciate it!

obtuse hound
#

Yeah, those are the most actionable and easy things to add to an existing integration now. One other thing you can do, that can often be too cumbersome, is tracking how many times they have tried to confirm each payment intent and cancelling the intent after too many attempts. Even a high limit like 100 would almost never be reached by a legitimate customer but is way less than what a bad actor could try without that limit.

#

Trying to think of more actionable things for now. Will get back to you

wanton latch
#

Oh interesting. Thanks @obtuse hound - we will do the three I mentioned first, but already sent the beta link to the dev team to investigate. This is great.

#

I appreciate it!