The new ‘Pay with Stripe’ button makes online payments feel better
thenextweb.com
thenextweb.com
But...it is also an indication of a change coming to a segment that has seen a decade of stagnation.
And that is beautiful.
I mean, normally you'd first be redirected to a trusted payment site and verify its SSL identity in the browser URL bar. Then you'd know that the trusted site will do things properly from there.
But in this case, are you just supposed to trust blindly that the Stripe-looking payment form popping up on some semi-random site will really be submitted to Stripe? Am I missing something?
Yes: most customers don't think about the question you're posing.
For that question to even arise in a customer's mind, they would have to know what an iframe is. Otherwise, it's just a cool little popup that the website opened.
This button is the first step for stripe to start being a trusted name by more skeptical e-customers.
Of course I realize that 'normal' people might trust anything, but it still won't make me trust it any more. So I'm not quite sure in what situation I would personally ever be able to use these nice Stripe button payments.
I once sent a letter to Steve Jobs saying that the MacOS (and other operating systems) were susceptible to phishing by applications, which would simply present a dialog that looks very much like the System Security dialog, and thereby gain the user's root password.
The solution is to have an area where only the operating system can draw (and which cannot be screen-captured, the same way Apple currently does with DRM movies). In this area, the system would present to the user a phrase which the user selected when setting up their account.
This would prevent phishing, as users would be trained to look for the phrase (and / or icon ... the reason you can't have an icon alone is because the phisher could get it right 1 out of N times).
Now, on the web there is a similar thing you can do! When someone places KEYBOARD FOCUS in your password box, and starts typing the correct password, you display the icon + phrase that you previously selected when setting up your account. If the phrase doesn't pop up or is different, you know you're being phished.
THIS is a great way to stop phishing on the web. Anyone impersonating you will not know what phrase to display. Only by starting to type the correct pass phrase will they get this information. On the other hand, they won't be able to place anything fake over the password input box and capture your input, because the phrase only appears when you type IN the password input box, which the attacker can't get to, thanks to the cross-domain security in browsers!
I guess if your site is using the default Bootstrap theme, then that's great, but in and of itself it is not eye-catching IMO.
Last night when I commented, the title was something along the lines of:
> The new ‘Pay with Stripe’ button is gorgeous
But now this morning, it's:
> The new ‘Pay with Stripe’ button makes online payments feel better
...which makes my comment seem like a critique out of left field.
Actual link to the site (Stripe): https://stripe.com/docs/button
This aesthetic choice doesn't seem to change the friction much. We're still typing in 16-digit codes by hand.
All due respect for Stripe, iframes are a potential security hole waiting to happen. iframes open many possibilities for exploits. I doubt we've seen all of them yet.
After another spate of PayPal randomly refusing my customer's payments, I've just spent most of my day searching for an alternative, AGAIN. Stripe, Dwolla, you name it - all closed to non-US residents.
US-based companies have a significant advantage here. They can sell globally because the rest of the world is used to paying in US dollars. But North American customers are paranoid about paying in other currencies, and don't understand the concept of exchange rates.
If anyone can tell me how to get an account with ANY mainstream US payment processor (except PayPal), I would be forever in your debt. There is a HUGE opportunity here. There are thousands of reputable companies from reputable countries that would jump aboard within days.
And The Next Web just dropped another notch on the news sites I trust list. I have to stop clicking those links. Wasn't this the same site that copied someones blog post basically word for word without giving them credit? Quick, check to see if this same story appeared somewhere else first.
Then you wouldn't trust any non-brand-name site that sells things via credit card charges (which makes you fall outside of the entire e-commerce consumer space).
Stripe isn't for Amazon and eBay, it's for those thousands of other sites out there that accept credit cards. If you would shop there using an inline payment form, you would still shop there with the modal <div> payment form. Believe it or not, people trust and use these kinds of sites every day.
Someone please tell the author that web design components do not have any emotions. The feeling could never be mutual.