Privacy and Web Payments

Privacy and Web Payments

Ian Jacobs

December 2019

Background

EMV® 3DS Design Goals

Different EMV® 3DS Trust Environments

Some Comparisons

SDK JS
Software Certification Yes No
Data Encryption Yes No
Unique ID Yes No
UX Controlled* Yes No

Web approach: Browser fingerprinted via injected JS from issuer.

*Not covered in this deck.

EMV® 3DS on the Web

Note: We expect similar flows with payment handlers instead of merchant-side PSP.

Limitations to this Approach

How can we improve this?

On Cookies

On FIDO2

Discussion Topics

Questions from EMVCo (1/3)

Questions from EMVCo (2/3)

Questions from EMVCo (3/3)