zlacker

[parent] [thread] 4 comments
1. swyx+(OP)[view] [source] 2020-04-21 17:56:59
title is a little sensationalist, i find that a little hard to forgive :) it is well understood any anti fraud system records movement. how does your analysis fare on Google's reCAPTCHA v3?

or rather the actual issue, the x00,000's of sites that actually record movement for product research and, yes, marketing? sensationalizing this issue on stripe, which is a probable good actor, doesn't help the sites and web users deal with the real bad actors.

but its a well written article with solid recommendations so kudos for that.

replies(3): >>mtlync+g1 >>falcol+u1 >>dang+C7
2. mtlync+g1[view] [source] 2020-04-21 18:02:33
>>swyx+(OP)
> it is well understood any anti fraud system records movement.

I don't think that's true of every anti-fraud system. I've integrated PayPal checkouts by pasting some HTML on a single page and that works fine. I'm sure it works better if you can record movement, but that doesn't necessarily mean I'm okay with handing over so much data to achieve those gains.

> how does your analysis fare on Google's reCAPTCHA v3?

I haven't looked too carefully at it, but my understanding is that reCAPTCHA 3 works if you place it on a single page. If reCAPTCHA is directing users to place it on every page of their app and not making it clear that Google's tracking it, I'd have a problem with that as well. From a cursory look at Google's documentation, they don't seem to be doing that.

3. falcol+u1[view] [source] 2020-04-21 18:03:56
>>swyx+(OP)
No, it’s not well understood. Perhaps you, and people in your direct field understand this, but does an average web developer who is reading Stripe’s documentation? Does a consumer?

Silent, given the lack of documentation or notification, is 100% appropriate here.

replies(1): >>lowan1+Zd1
4. dang+C7[view] [source] 2020-04-21 18:38:04
>>swyx+(OP)
We've changed the title - see https://news.ycombinator.com/item?id=22937739
◧◩
5. lowan1+Zd1[view] [source] [discussion] 2020-04-22 04:29:38
>>falcol+u1
I mean, the docs literally spell this out, so I'm not sure how much you or the author of the article wants their hand held:

> To best leverage Stripe’s advanced fraud functionality, include this script on every page, not just the checkout page. This allows Stripe to detect anomalous behavior that may be indicative of fraud as customers browse your website.

https://stripe.com/docs/js

[go to top]