Comment 10 for bug 527701

Martin Meredith (mez) wrote :

Personally, a padlock icon in rhythmbox wouldn't suffice for me, as that could easily be "faked" ... and, well, we could potentially have a MITM with a cheap SSL certificate (CACert maybe, if that's included).

I'd personally like to see an external page load up in my browser, where I can confirm the details and "register" my card or paypal account (though, whether you're storing the CCs is a different matter! - and a bigger security risk!)

It's a bit of a tough one really... if not storing, maybe an external site that allows you to buy "vouchers" that get linked to your U1 account? And for paypal - a "payment agreement" ?