Since the website gets to specify the payment processor link, I'm very curious to see how Chrome will protect people from malicious websites, how it handles the problem of signing people up to a payment processor, how it will handle informing people that a payment is about to happen, what processor will handle it, how to stop it before it happens, and etc.<p>The WIP spec (<a href="https://webmonetization.org/specification/" rel="nofollow">https://webmonetization.org/specification/</a>) is pretty handwavy about all these issues (and, concerningly, is specifying important security mechanisms as SHOULDs rather than MUSTs, but that's a different discussion), which means it's going to be up to Google to decide how these things are dealt with.