Stripe Integration for Twilio Pay
stripe.com
stripe.com
For example, when I key in my card number, my phone carrier will know it, the routing carriers know it before it reaches Twilio. How is my card information safe? I guess I'm missing something here.
So, if attackers wants to get card details, they need not attack the business or Twilio (because it might redact these when they see <Pay>, but they can simply access logs of the middlemen for DTMFs. Concatenate all those per call, and there we should have all card numbers, expiry dates and CVC/4DBC.
Not sure how Twilio is doing it though. Unless they use some awesome encryption method to encrypt all these numbers so no one in middle can see them.
Why would they be receiving the tones once the connection is made? Isn't it the same as me just whistling at particular frequencies? I didn't think it was sent in a different manner.
Or do you mean it goes through the carrier just like if you spoke your card number over the phone to someone?
1. In the regular audio stream (AKA in-band) so anyone who can listen to the phone call, can also listen to these tones. These tones can be mapped to the digits pressed.
2. In a separate RTP payload (AKA out-of-band) so not everyone can read / listen to this stream of signals / tones. RFC 4733 (earlier it was RFC 2833) specifies the format of this RTP payload. This is what the payment via phone systems might be using.
There is a secure RTP with encryption support, but I am not sure if it can be implemented end-to-end to avoid anyone in middle (not a man-in-middle attacker, but a genuine carrier / network) to see these DTMFs. Just unable to imagine how this works :)
It would be great to hear a demo of what <Pay> sounds like, particularly the error handling.
I absolutely get the benefit of insulating your agents from the billing data. Not so keen on an abrupt switch to touch-tone inputs during a call though.
I recently pay my home insurance's renewal that way (Europe).
However, these days many systems use voice recognition rather than having to key in numbers. I'm guessing that this is on Twilio's roadmap.
Alternatively, I built https://checkoutpage.co to create hosted payment pages for Stripe that are accessible by url, similar to Razorpay's payment links.
[1] - https://trolley.link
It's kinda hard to abuse recently. You can do heavy geo locking in order to not get fucked over by abuse to other countries.
If you don't buy UK numbers, I think UK is locked down as well.
Not sure what happened with that but looks like essentially the same idea here. Always thought it was pretty niche now everyone has a browser in their pocket.
In the past, if you iframe'd a payment processor site, you didn't need to be PCI compliant while the new spec requires everyone who is involved in the process to be compliant.
I wonder if this will be the future of payment processing, just outsourcing to Twilio and Stripe.
" For a more personalized experience, employees can also walk customers through an order over the phone: when it’s time to collect the payment, the agent activates Twilio <Pay>"
Of course, larger places have their own non-Twilio Voice PBX and lines, so I'm not sure if this approach only works if the call originally came in via Twilio.
https://www.twilio.com/docs/voice/tutorials/how-capture-your...