Live data from Hacker News

Show HN: Card – An interactive CSS3 credit card form

jessepollak.github.io

111–117 of 117 posts

Re: Show HN: Card – An interactive CSS3 credit card form

#111

Earlier quoted context omitted.

That's a far cry from Make your credit card form better in one line of code and With one line of code.. $('form').card({ container: $('.card-wrapper') }); You get.. Animations for 4 different card types An intuitive experience for your users Pure CSS, HTML, and Javascript (no images) 100% free and open source Which certainly could be used by someone who doesn't understand all this. All I am saying is that for us as d…

If somebody who doesn't know what they're doing is writing a CC form, you've already lost. Making app development easier isn't "dangerous" because it allows less experienced people develop applications. You will always have people making mistakes and screwing up security, regardless of the actual ease of development. The more the developer has to do, the more they can screw up.

This is what my point is: as much as the customer has to slow down and say, "Wait a second, is this legit?" - so do we.

That doesn't mean the customer won't conclude it is legit, or that we don't conclude the same thing.

Recall that I had responded to,

>Looks gorgeous. I can't help but wonder if people unfamiliar with technology and ecommerce would be deterred by such a form?

Certainly I personally would be deterred (to an extent) from using this form without at least a cursory audit and verifying the identity of the person who wrote it.

This will naturally be less and less important the more eyeballs this sees. But as a simple tool, perhaps it is not that many.

Do remember that if I were wanting to get my hands on people's credit cards, getting developers to use this kind of script while having a well-hidden side channel (perhaps quite well-hidden - it could somehow encode cc details in the timing delays to a different server, potentially, so that it is not at all obvious that the delays even correspond with the data, it could just look like visualizations getting loaded as the person types) -- then this would be one of the more clever ways I could go about doing so.

I don't see how we're 'arguing' about this? We need to check what we are using, just like customers need to check that this is legit.

Re: Show HN: Card – An interactive CSS3 credit card form

#112
Used in production today on an internal tool that we do some billing/card running on. After some small jquery options struggles, it worked as it says on the tin.

Interesting reaction by test group when deploying....test group being a small group of coworkers. Without announcement, they immediately were untrusting of it and thought it was somehow consuming the credit card information maliciously. This is the security climate we find ourselves in. heh But after assuring them, they thought it was pretty neat/fun.

Fun.

Re: Show HN: Card – An interactive CSS3 credit card form

#113

Looks great. Few notes: 1) On the already crowded payment form, I don't want to devote a hell of a lot of space to something that is otherwise inconsequential (a picture of a credit card) 2) Is it a great idea to broadcast someone's card numbers so clearly? The graphic is so obviously a credit card, it would be easy for any onlooker to spot and steal. Really, this seems like aesthetics for aesthetics' sake, which I t…

You're right, point 2 is THE show-stopper for this. It looks amazing, but if amazon or the likes ever tried this I'd close my account - credit card security, in this day, is not the place for gimmicks. Sorry.

Re: Show HN: Card – An interactive CSS3 credit card form

#114

Earlier quoted context omitted.

If somebody who doesn't know what they're doing is writing a CC form, you've already lost. Making app development easier isn't "dangerous" because it allows less experienced people develop applications. You will always have people making mistakes and screwing up security, regardless of the actual ease of development. The more the developer has to do, the more they can screw up.

This is what my point is: as much as the customer has to slow down and say, "Wait a second, is this legit?" - so do we. That doesn't mean the customer won't conclude it is legit, or that we don't conclude the same thing. Recall that I had responded to, >Looks gorgeous. I can't help but wonder if people unfamiliar with technology and ecommerce would be deterred by such a form? Certainly I personally would be deterred…

I don't really understand your point. The thing about timing channels is absurd - we have the code right in front of us. Right there. It either calls third-party servers or it doesn't, and we can see that. Very easily.

The idea that anyone would successfully steal CC info by putting up an open-source client-side jQuery plugin under his real name is just silly. It's not something that you ever have to worry about in the real world. Sure, I'll concede that if a number of absurdly unlikely things happened, something like this could steal CC info.

Besides, you're missing the point. We're paid to vet this stuff. Customers aren't. Your choice of whether to use this or not harms no one - but customers being scared of an odd-looking CC form is harmful to business, and a valid and interesting point.

Re: Show HN: Card – An interactive CSS3 credit card form

#115

Looks gorgeous. I can't help but wonder if people unfamiliar with technology and ecommerce would be deterred by such a form? It might give some users the impression that the website is "copying" the credit card. It would be interested to test the opinions of non-tech savvy users.

This is amazing, I love how it handles the CVC even on AmEx. The only way this could be better is to type directly on the card or move the fields above (mobile) or to the side of the card to make them more prominent. This is great work.

You mean like this: http://kenkeiter.com/skeuocard/

Re: Show HN: Card – An interactive CSS3 credit card form

#116

Earlier quoted context omitted.

This is what my point is: as much as the customer has to slow down and say, "Wait a second, is this legit?" - so do we. That doesn't mean the customer won't conclude it is legit, or that we don't conclude the same thing. Recall that I had responded to, >Looks gorgeous. I can't help but wonder if people unfamiliar with technology and ecommerce would be deterred by such a form? Certainly I personally would be deterred…

I don't really understand your point. The thing about timing channels is absurd - we have the code right in front of us. Right there. It either calls third-party servers or it doesn't, and we can see that. Very easily. The idea that anyone would successfully steal CC info by putting up an open-source client-side jQuery plugin under his real name is just silly. It's not something that you ever have to worry about in t…

we're not disagreeing

Re: Show HN: Card – An interactive CSS3 credit card form

#117

Earlier quoted context omitted.

I am fully aware of PCI, I used to develop billing systems, Utility Billing Systems to be exact a heavily regulated industry that has even more rules than normal ecommerce. Further anyone that collects credit card data must be PCI Compliant, period. There are 4 Levels of PCI Compliance and depending on what your doing with the Credit Card data and how many transactions you process determine where you fall, many small…

Well, some people that I contacted verify my story and I worked on payment systems as recently as 6 months ago. But what statements like that do to bolster a position is not clear to me. I'm not sure what you're trying to achieve here, some kind of anecdotal proof that I'm wrong? You're completely missing the point of the sub-merchant situation, one where you have a contract with both the card companies (one for VISA…

No you are not under any obligation to post anything, however when posting something you claim to be a violation of law or policy is customary to support that claim with citations to where you have gained this knowledge. To date you have not posted any citation to support your claim in a verifiable manner. You have posted no terms, no laws, given no citations of any regulations or policies that are open to the public review, My own investigations have found nothing in any written documentation to support your claims. I believe you are wrong, and have asked you to provide a citation back your claims, which to date you have not.

If this was an official position of either Visa, MC, or an "IPSP" you would be able to post a link to their official terms that spell out that position, since you can not your comment should be ignored.

As to PCI Compliance, I will say again, ALL PERSONS TAKING CREDIT CARD MUST BE PCI COMPLAINT. Small, medium, large it does not matter, if you accept credit cards at all you much be PCI Compliant. Level 4 Compliance is a joke, and even the smallest of small business can become Level 4 Complaint...

Level 1, which is what a Walmart would be, is hard to get and most online merchants do not even attempt to get that.

Post reply on HN