#decline-issue-report

1 messages · Page 1 of 1 (latest)

glad ploverBOT
obsidian fossil
#

Can you share the request ID for this?
req_xxx

#

OR the PaymentIntent ID?

thin dagger
#

req_vsgprFxfI9RAO2

obsidian fossil
#

AFAIK PaymentIntents generated via Checkout don't support manual confirmation. Is that what you're trying to do?

thin dagger
#

earlier it was a thing though

thin dagger
#

you should see this first

obsidian fossil
#

The idea with Stripe Checkout is to provide customers a way to pay for the product using Stripe hosted UI.

If you're using PaymentElement then you can just use the PaymentIntents API, no?

thin dagger
#

someone sent me this , is this usual >

obsidian fossil
#

Not sure I follow, what are we looking at?

thin dagger
obsidian fossil
#

Ah you mean checking out with an incomplete card number, no that shouldn't be possible.

Is there a page/link I can use to reproduce this?

thin dagger
#

you must be knowing few weeks back card cvc was also a critical flow threat which was patched recently

obsidian fossil
#

Not exactly security threat but in order to understand what's going on here we'll need to look at how the checkout is behaving for you.
Can you share an example checkout session so I can reproduce?

thin dagger
obsidian fossil
#

No, I understand now since you shared a video

#

looking into it

thin dagger
# thin dagger

these checkouts also show "powered by mohio" instead of stripe

thin dagger
obsidian fossil
#

Gotcha. I've flagged this internally and a colleague is looking into it.
It could be a scammer with Checkout clone trying to scam folks but not sure since we don't have enough info.

#

@thin dagger yes, please use this thread for follow ups

thin dagger
obsidian fossil
#

Yes, we will post an update here

thin dagger
thin dagger
thin dagger
#

carding”,“account testing”, and “card checking.”

thin dagger
#

@obsidian fossil

obsidian fossil
#

We are currently investigating and I am working with multiple users on discord at the same time. Please be patient.

If you'd like to report this via email/chat then you can reach out to our support team via
https://support.stripe.com/?contact=true

They can help escalate this via proper channel.

#

I asked a colleague to look into the video, they checked the checkout session in the video and looks like nothing was bypassed. It is most likely a scam video that uses a dummy checkout clone.

If you're still concerned then please reach out to our support team via the link I shared above. They can help further.

thin dagger
thin dagger
#

aren't interested like you. @obsidian fossil

obsidian fossil
#

You can ask them to escalate to the right team for reporting issues like this

thin dagger
#

I am sure there was a email dedicated to this

#

issue , will send them directly

obsidian fossil
thin dagger
#

Alsothiskeyseemstobeliveandworking

#

I found someone s live api key

obsidian fossil
#

please don't share live secret keys on public server

thin dagger
#

It's not my

obsidian fossil
#

I understand that but you still shouldn't share it

thin dagger
#

Found it somewhere

#

I understand but I shouldn't be able to have it right?

obsidian fossil
#

Yes it should be kept safe. I understand you want to help by reporting it but there's nothing our team on discord can do to help.

You can report it via support and they can escalate if needed
https://support.stripe.com/?contact=true

thin dagger
#

But it takes ages for your team to

#

Like take action

#

Can't you revoke that key

#

That's only my request

glad ploverBOT
thin dagger
#

Woah

#

Admin 🙂

obsidian fossil
#

Not something our team on discord can handle. We work with developers building apps using our APIs/SDKs.
We don't have tools or workflows to revoke keys

thin dagger
#

But you do have direct contact with the related team

spice cliff
#

@thin dagger Let's not argue indefinitely. Please work with our support team for help directly, we can not help here.

thin dagger
#

Ok I can stop here, not rude about this but you don't want your company to be helped 🙂

thin dagger
#

They are done via these public secret keys

#

90% of them

spice cliff
#

Please work directly with our support team