this post was submitted on 01 Jul 2026
400 points (99.5% liked)
AssholeDesign
11435 readers
1 users here now
This is a community for designs specifically crafted to make the experience worse for the user. This can be due to greed, apathy, laziness or just downright scumbaggery.
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Hate to break it to you, but placing the order at all is already giving them all that data.
It's more about consent to save the data rather than just passing it on to the payment processor. Different attack surface, as getting it without it being saved would require their codebase be compromised or some sort of man in the middle attack (which is difficult/impossible with encryption, if it's done right), or compromising the payment processor themselves. If the data is saved, all of those work plus any brief security breach that gives access to the database, which will be the most common type of breach out of all the ones that could expose the CC info.
Sure they could still be saving it, but then if there is a breach, it will be discovered that not only did they have a breach but they made it worse by saving financial data without user consent, which would increase the damages for the class action suit for the breach. In theory, at least, hard to tell how it would work out with today's level of corruption.