Suppose I do an online shopping they are asking me to enter my card details like
ID: 660870 • Letter: S
Question
Suppose I do an online shopping they are asking me to enter my card details like four digit number(whatever related to that) and they are asking me to enter the PIN number too.
If I enter all this things, Can't they get all keystroke from me through Javascript and crack my passwords, card details etc ?
I surfed for safety tips on online shopping, few article suggest to check whether it is a secured session layer supported website Means SSL, Here I have one more doubt SSL is used for Secure Transaction Between Client Browser and server so there won't be any intruder to pretend to me or some attack, what if the server person itself capture this details and make a duplicate card or something and they get all money etc?
If I use money transfer from other service like for example (paypal,stripe) then it is completely fine because they use OAuth but What if it is for internet banking? I'll be shopping through my bank account. Shop Website server can crack my passwords etc right?
Explanation / Answer
I think you might be mixing a couple of risks up here.
If you are surfing a site and purchasing goods from them, then they will inevitably have access to any data you enter into their site. This would include the username/password that they use on the site and likely any payment card details that you use to pay for things on their site. This is because that data needs to be transferred to them to complete the transaction (no JavaScript needed)
As you say if they use a 3rd party site (e.g. paypal) to process the payment they your credentials for the payment site shouldn't be accessible by the shopping site, although it's here that if they were malicious they could try do something like redirect you to a site which looks like Paypal but isn't...
In terms of accessing your banking details, again, as long as you're not using the same credentials on the banking site as on the shopping site, they shouldn't be able to access your banking credentials.
Related Questions
drjack9650@gmail.com
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.