If you don’t need a PIN for your card in Apple Wallet and don’t need a PIN to use Apple Wallet, how is that safe?

I’ve just added a card to my Apple Wallet and noticed that I didn’t need a PIN. Now since Apple Wallet is apparently already "secure", I don’t need a PIN to use it either.
Is this a loophole or am I missing something?

Continue reading If you don’t need a PIN for your card in Apple Wallet and don’t need a PIN to use Apple Wallet, how is that safe?

How can a credit card processor tell I had a trial with a specific company before if every detail provided is different?

Consider the following scenario: I signed up for a free 7d trial of a $200/y "AI" subscription product (not OpenAi) — provided username and an e-mail address and was forwarded to a Stripe checkout page for card verification.
Whi… Continue reading How can a credit card processor tell I had a trial with a specific company before if every detail provided is different?

how should a web application verify a redirect comes from a trustworthy source?

This document has a sequence diagram (annotated and shown below) explaining how Stripe handle’s a Checkout Session.
My question : When a customer is returned to the successUrl = www.example.com/some/specific/path, how can www.example.com (… Continue reading how should a web application verify a redirect comes from a trustworthy source?

Online stores may not be as secure as you think

Credit card skimming is on the rise for the holiday shopping season, according to Malwarebytes. Online stores are not always as secure as you might think they are, and yet you need to hand over your valuable credit card information in order to buy anyt… Continue reading Online stores may not be as secure as you think

Showing a license/id to a shopping website, worth it? [duplicate]

I’m wondering if anyone here has ever decided to show their driver’s license or ID of any sort to be able to shop at a website. I was personally asked to do this along with a facial verification. I was thinking if I were to show my driver’… Continue reading Showing a license/id to a shopping website, worth it? [duplicate]

PCI-DSS Compliance: SSL Tunneling Credit Card Information Through A HTTPS Mobile/Residential Proxy Service to A Destination Service

If a PCI compliant service decides to SSL-Tunnel credit card information via an independent residential/mobile proxy service to a destination payment service, would this protocol still be PCI compliant?
Since the credit card information is… Continue reading PCI-DSS Compliance: SSL Tunneling Credit Card Information Through A HTTPS Mobile/Residential Proxy Service to A Destination Service