Is there any problem with this? I've had two or three payments requiring my LaBanquePostale password now and while I found it curious that they ask for so many factors of authentication (credit card details, sms-pin, password) I assumed whatever info I enter in that iframe was safe and only accessible to the bank, isn't that how it works?
That's the thing, even if they use an IFrame, I am not supposed to check everytime. The only thing I should have to check is whether the domain name in the address bar is the one of my bank for giving such confidential credentials.
Because as a client I'm not supposed to know anything about wlp-acs.com or adyen.com or whatever site the merchant site redirected me to.
Here the password they request is a lot more important than any one transaction would, as it allows full access to your accounts.