Issue metadata
Sign in to add a comment
|
payment check enabled by default
Reported by
sumanman...@gmail.com,
Nov 15
|
||||||||||||||||||||||||
Issue descriptionVULNERABILITY DETAILS In google chrome, by default the option "Allow sites to check if you have payment methods saved" is enabled. I think this is a bug and a security issue. VERSION Chrome Version:Version 70.0.3538.102 (Official Build) (32-bit) Operating System: Windows 10 REPRODUCTION CASE Make a clean installation of Chrome and check the flag in the settings FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION N.A CREDIT INFORMATION Reporter credit: sumanmanuel@gmail.com
,
Nov 15
This is intentional and is by design. Not sure there's anything to do for this bug report? +durgapandey@, +gogerald@.
,
Nov 15
Thank you for the quick response. I think this option should be disabled by default and only enabled if a user requires. If i am not wrong, accessing the payment details without the known consent of the user is a security fault.
,
Nov 15
Re comment #3: I think there is some confusion about "payment details" (cc #s, addresses, etc.) vs. "available payment methods" (do you have a payment handler that can do CC#? Internet Payment Vendor XYZ? etc.). This default-allowed permission only gives details about the later, not the former. Notably, this does _not_ expose data from autofill. PaymentHandler/PaymentRequest actually _reduces_ the amount of personal data that is sent to the initiating site (as it allows the site to directly request a payment be processed by a separate handler).
,
Nov 19
As per comment#4, requesting reporter to respond back on it. Hence adding Needs-Feedback label. Thanks!
,
Nov 19
,
Nov 30
As mentioned above this is working as intended. The only information is that is exposed is whether the user is able to make a payment with a specific payment method. This was not seen as too much of a privacy issue, so there is only an opt-out. |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by cthomp@chromium.org
, Nov 15Components: Internals>Permissions>Model UI>Browser>Payments Privacy
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Summary: payment check enabled by default (was: Security: payment check enabled by default)