Have you taken note of this possible vulnerability? You guys need to be more careful about security. You may only get one shot at this, if you get bad PR this early by getting hacked.
The Stripe button poses a similar problem, even if credit card number and cvc are arguably not as bad as actual login data.
But it is much easier to create a frictionless user experience if you do not have to redirect people to somewhere outside your side.
I recently implemented paymill payments and also there the only assurance for the customers is the 3D-Secure iFrame, if their credit card is 3D secure enabled ...
http://www.reddit.com/r/Bitcoin/comments/14c7q0/coinbase_lau...