You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<p>A consequence of this specification’s third-party authentication ceremony is
1349
-
that even in a valid transaction (i.e. one that the <adata-link-type="dfn" href="https://w3c.github.io/webauthn/#relying-party" id="ref-for-relying-party③⑥">Relying Party</a> is
1350
-
expecting), a third-party provides the transaction details that are shown to
1351
-
the user:</p>
1348
+
<p>The bank can and should protect against spoofing by <ahref="#sctn-verifying-assertion">verifying the authentication assertion</a> they receive to
1349
+
ensure it aligns with the transaction details provided by the
1350
+
merchant.</p>
1351
+
<p>That is because a consequence of this specification’s third-party
1352
+
authentication ceremony is that even in a valid transaction (i.e. one
1353
+
that the <adata-link-type="dfn" href="https://w3c.github.io/webauthn/#relying-party" id="ref-for-relying-party③⑥">Relying Party</a> is expecting), a third-party provides the
1354
+
transaction details that are shown to the user:</p>
trust that the merchant showed the user the correct amount in their checkout
1369
1372
flow (and any fraud discoveries are post-payment, when the user checks their
1370
1373
account statement).</p>
1371
-
<p>With Secure Payment Confirmation, the bank can (and should) instead <ahref="#sctn-verifying-assertion">verify the cryptogram</a> that they receive, to
1372
-
ensure that it aligns with the transaction details provided by the merchant.</p>
<p>As this specification builds on top of WebAuthn, the <ahref="https://www.w3.org/TR/webauthn-3/#sctn-privacy-considerations">WebAuthn Privacy Considerations</a> are
1375
1376
applicable. The below subsections comprise the current Secure Payment
0 commit comments