#Arvind hariharan

1 messages · Page 1 of 1 (latest)

buoyant pierBOT
flint sequoia
#

Hi there, how can I help?

tawdry forge
#

Hi jack. Wanted to understand how stripe handles Cross site scripting attacks vulnerabilities since Elements host all form inputs containing card data within an iframe served from Stripe’s domain.

#

Do we need to do anything from our end to prevent it?

flint sequoia
#

Are you asking how to prevent attacks to your website or to Stripe?

tawdry forge
#

since Apple Pay or google pay pop ups opens through an i Frame which is hosted by stripe elements. How is stripe preventing the cross site scripting attacks for those?

#

yeah i am asking how to prevent attacks to stripe's iframe

#

if it is handled by stripe then how is that handled?

flint sequoia
#

1/ Apple Pay / Google Pay payment sheet is not an iframe.
2/ These payment sheets are provided by Apple/Google, not Stripe.

tawdry forge
#

okay so all these security related vulnerabilities is handled by Apple or google right. Nothing to be taken care from our end correct?

flint sequoia
#

Yes. If you want to know more, I'd suggest you reaching out to Apple and Google directly.