TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Why is “Verified by Visa” integrated as an iFrame?

4 点作者 andor超过 3 年前
The PSD2 regulation in the Euro-zone now requires two-factor authentication for online credit card payments. So for every payment with my credit card, &quot;Verified by Visa&quot; or &quot;Mastercard SecureCode&quot; pop up and ask me to authenticate. <i>Depending on the bank, the authentication can require the same credentials used to login to the online banking account.</i><p>The authentication requirement is a bit of a hassle (CC network should bear the fraud risk), but the part that seems absurd to me is that <i>the integration is done as an iFrame</i>. That means ordinary users are now trained to enter their banking credentials on random websites—the opposite of what they learned in years of phishing education.<p>Does anyone understand how it came to this?

3 条评论

detaro超过 3 年前
I&#x27;ve only ever seen it as a redirect to the bank website? (And with my bank that then asks for me to confirm the transaction with an authenticator app, it doesn&#x27;t request otherwise usable credentials)
评论 #28854744 未加载
high_byte超过 3 年前
iframe offers sandbox to your data. it allows websites to show info such as your email address from Google or services without said websites knowing your address. or to like a tweet with your account. or to leave a comment through Facebook. or to display targeted ads. or to enter credentials with somewhat safer environment. I say somewhat because it is safer done right but there will always be people entering their private crypto keys that totally throw off the statistics.
armchairhacker超过 3 年前
idk if iframe limits what the host site can read from the embedded site, but it could add more security because the host site can’t get your bank data.<p>As far as getting users accustomed to entering data in iframes, the average user won’t be able to tell what part of a site is iframe or not. And idk how much of a difference it makes if you can tell - any random site you enter your data could potentially steal it.