Results 1 to 2 of 2
  1. #1
    Join Date
    Dec 2008
    Location
    New Zealand
    Posts
    18
    Plugin Contributions
    0

    Default credit card security issue

    Hi,
    I have just had a customer raise security concerns over our Zen Cart web site. She noticed that the credit card info is stored by the browser. She was surprised to find that when placing a repeat order that her cc number automatically 'popped up' in the cc box on the order payments page.

    I have confirmed that this does in fact happen (using FireFox). And the scary thing is that even if I log in as a different user, the same cc number pops up in the box (You have to type the first digit, then the drop down appears with the full cc number).

    I will try and fix this myself, but would appreciate any comments or help.

    Using Zen Cart 1.3.8a

    Tony

  2. #2
    Join Date
    Apr 2006
    Location
    London, UK
    Posts
    10,569
    Plugin Contributions
    25

    Default Re: credit card security issue

    This isn't being stored by Zen Cart, but by her browser. The autocomplete function is built into Firefox and also come with the Google Toolbar. So it's her browser that's storing the information and re-inserting it.

    Theoretically site's shouldn't interfere with the choices that users make for their browser settings (even if they are defaults and they don't know they've made them). So the standards authorities haven't provided a way to do so.

    However, IE and Mozilla have slipped some non-standard features into their browsers, so that adding autocomplete="off" to the credit card fields input will disable the facility, though it will also cause the page to fail validation, though in this case that's probably acceptable.
    Kuroi Web Design and Development | Twitter

    (Questions answered in the forum only - so that any forum member can benefit - not by personal message)

 

 

Similar Threads

  1. Credit Card security issue
    By cushietushies in forum Addon Payment Modules
    Replies: 6
    Last Post: 5 Sep 2008, 02:18 AM
  2. Credit Card/Security Information
    By untitled10101 in forum General Questions
    Replies: 1
    Last Post: 15 Apr 2008, 03:52 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR