为什么使用明文作为信用卡安全码?
我很好奇为什么所有大多数支付网关网站都使用明文输入来获取安全代码。
如果用户将安全代码放入密码模式文本框中,不是更安全吗?
请给我启发
I'm curious about the reason why all most payment gateway site use clear text input to take security code.
Isn't it more secure if users put their security code in password mode textbox?
please give me enlightenment on this
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(2)
如果您为此使用了密码框,那么您究竟向谁隐藏了安全代码??据推测,用户手里拿着信用卡,回头看的人只能看到卡上的号码,而不是屏幕上的号码。
Jakob Nielsen 最近提出了停止密码屏蔽的案例,这意味着所有人< /em> 密码字段。
Bruce Schneier 在他的文章密码屏蔽的优点和缺点。如果有人讨论密码屏蔽是否与密码字段相关,我什至不会考虑将其用于 CCV 字段。
操作系统中输入无线密码的密码提示可能有一个“显示密码”选项。
If you used a password box for this, who exactly are you hiding the security code from? Presumably the user has their credit card out, in their hand, and somebody looking over their shoulder can just see the number on the card instead of the screen.
Jakob Nielsen recently made a case to Stop Password Masking, that means for all password fields.
Bruce Schneier added his opinion in his article The Pros and Cons of Password Masking. If there's discussion about whether password masking is relevant for password fields, I wouldn't even consider using it for CCV fields.
The password prompt in your OS for the wireless password probably has an option to "show password".
希望数据使用 HTTPS 传输。使用密码字段甚至可能会让浏览器提示是否保存该值以供以后使用,因此可能不会使其更安全。 (但是,你是对的,使用纯文本字段可能会让浏览器也记住它。)至少纯文本对用户来说更容易。
Hopefully, the data is transmitted using HTTPS. Using a password field might even make the browser prompt whether to save the value for later use, and hence might not make it more secure. (But then, you're right, using a plain text field might make the browser remember it as well.) At least plain text is easier for the user.