#Arvind hariharan
1 messages · Page 1 of 1 (latest)
Hi there, how can I help?
Hi jack. Wanted to understand how stripe handles Cross site scripting attacks vulnerabilities since Elements host all form inputs containing card data within an iframe served from Stripe’s domain.
Do we need to do anything from our end to prevent it?
Are you asking how to prevent attacks to your website or to Stripe?
since Apple Pay or google pay pop ups opens through an i Frame which is hosted by stripe elements. How is stripe preventing the cross site scripting attacks for those?
yeah i am asking how to prevent attacks to stripe's iframe
if it is handled by stripe then how is that handled?
1/ Apple Pay / Google Pay payment sheet is not an iframe.
2/ These payment sheets are provided by Apple/Google, not Stripe.
okay so all these security related vulnerabilities is handled by Apple or google right. Nothing to be taken care from our end correct?
Yes. If you want to know more, I'd suggest you reaching out to Apple and Google directly.