Results 1 to 3 of 3
  1. #1
    Join Date
    Feb 2008
    Location
    Ontario, Canada
    Posts
    8
    Plugin Contributions
    0

    Default Exporting Customer Accounts with Passwords

    We are probably going to be moving to a fully hosted ecommerce system. (Volusion) Nothing to do with Zen Cart. In fact we are very happy with Zen Cart overall and would prefer not to change, but it is getting harder and harder to keep everything PCI compliant. We would much rather focus on our business, rather than constantly deal with security patches, broken code caused by security patches and other bizarreness caused by security patches.

    In any case, our database contains about 5,000 customer records that we need to move to the new service. From our tests so far, this does not appear to be a problem, except for the customers passwords. I can see no way of moving these out of Zen Cart and into Volusion as they are encrypted.

    Telling 5,000+ customers that their passwords no longer work is not really a pleasant nor practical option, so how does one go about migrating passwords from one system to another?

    Ron

  2. #2
    Join Date
    Jan 2004
    Posts
    66,443
    Plugin Contributions
    279

    Default Re: Exporting Customer Accounts with Passwords

    Zen Cart's passwords cannot be unencrypted. They are encrypted using a one-way encryption method. This provides maximum security to the customer's private personal data.
    If you must retain those passwords, you'll have to alter the password-encryption code in your other system if you want it to be able to authenticate using the passwords currently in your database.

    If your issue is with PCI compliance, then perhaps you're hosted in the wrong place. There are several hosting companies out there maintaining solid PCI compliance while still offering shared hosting services to their clients operating busy Zen Cart stores.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  3. #3
    Join Date
    Feb 2008
    Location
    Ontario, Canada
    Posts
    8
    Plugin Contributions
    0

    Default Re: Exporting Customer Accounts with Passwords

    Thank you for the prompt reply.

    We are hosted with Peer1, a fairly well established hosting service. The problem is not them being able to keep the system patched and up to date. The problem is more about the side effects that the patches cause and the constant struggle to satisfy our PCI compliance provider.

    Even though Peer1 is very diligent in being sure the system is fully patched and PCI compliant. There is a very serious breakdown in communications between the patched system and the PCI compliance providers scanner. Security updates are not necessarily reported during system scans, and as a result we fail the compliancy scan every quarter. This triggers days and weeks of back and forth emails between me, Peer1 and the PCI compliance provider trying to prove to the compliancy provider that we are fully secured.

    This past quarters scan was the last straw, as our PCI compliancy provider is now insisting that we actually install a patch that will break the automatic updating process provided by Red Hat. They tell us that we will just have to be sure that all released patches are manually installed instead.

    Bottom line is, I have had enough of it. We are going to move to a fully hosted service and they can take care of all the PCI compliancy and constant software upgrade/patch/fix headaches. I just want to sell my products.

    Sorry for sounding off on this, but it has been a rough summer.

    I guess we will have to let 5,000 customers know that their old password will no longer work. No wonder people get so frustrated sometimes with online companies. Best practises for password migration should of been worked out by the industry as a whole years ago.

    Ron

 

 

Similar Threads

  1. v150 Exporting customer accounts & products to CSV
    By meljen in forum General Questions
    Replies: 5
    Last Post: 4 Jun 2014, 07:41 AM
  2. Problem with customer passwords??
    By touchclothing in forum General Questions
    Replies: 7
    Last Post: 22 Feb 2009, 11:31 PM
  3. Can a customer with 2 accounts be merged?
    By lyricwings in forum Managing Customers and Orders
    Replies: 2
    Last Post: 24 Jul 2007, 11:19 PM
  4. Exporting Customer Database and accessing passwords
    By Orders in forum Managing Customers and Orders
    Replies: 6
    Last Post: 21 Aug 2006, 10:04 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg