Results 1 to 10 of 10

Hybrid View

  1. #1
    Join Date
    Dec 2006
    Posts
    102
    Plugin Contributions
    0

    Default payflow pro - how can I stop display of card number?

    [FONT=Calibri]I running zencart 1.3.8a (will be upgrading soon)[/FONT]
    [FONT=Calibri]We have had a few customer complain that there CC number shows up on step 3 of 3 of the order conformation [/FONT]
    [FONT=Calibri]Is there any way to turn that off?[/FONT]

  2. #2
    Join Date
    Jun 2003
    Posts
    33,720
    Plugin Contributions
    0

    Default Re: how to remove credit card number from showing in order process

    On the confirmation page, there should only be a partial number showing - Are your customers saying the whole number is shown? What Payment gateway are you using?
    Please do not PM for support issues: a private solution doesn't benefit the community.

    Be careful with unsolicited advice via email or PM - Make sure the person you are talking to is a reliable source.

  3. #3
    Join Date
    Dec 2006
    Posts
    102
    Plugin Contributions
    0

    Default Re: how to remove credit card number from showing in order process

    Quote Originally Posted by Kim View Post
    On the confirmation page, there should only be a partial number showing - Are your customers saying the whole number is shown? What Payment gateway are you using?
    its a partial number, but I guess some customer do not like that, and view it a a security risk

    we are useing PayPal Pro

  4. #4
    Join Date
    Jan 2004
    Posts
    66,443
    Plugin Contributions
    279

    Default Re: how to remove credit card number from showing in order process

    The partial numbers (4 starting digits and 4 trailing digits) are acceptable according to official credit card industry regulations, and do not pose any quantifiable security risk.
    However, if you are running your site *without* SSL (ie: using https:// URL) then you have a completely different and very real security problem.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  5. #5
    Join Date
    Dec 2006
    Posts
    102
    Plugin Contributions
    0

    Default Re: how to remove credit card number from showing in order process

    Quote Originally Posted by DrByte View Post
    The partial numbers (4 starting digits and 4 trailing digits) are acceptable according to official credit card industry regulations, and do not pose any quantifiable security risk.
    However, if you are running your site *without* SSL (ie: using https:// URL) then you have a completely different and very real security problem.

    we have SSL, just would like to remove the partial numbers to make our customer (who do not know the official credit card industry regulations) feel more comfortable

  6. #6
    Join Date
    Jan 2004
    Posts
    66,443
    Plugin Contributions
    279

    Default Re: how to remove credit card number from showing in order process

    Is this just one one-time customer complaining or is this hundreds of repeat customers complaining?
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

 

 

Similar Threads

  1. Stop storing Credit Card Number in Database
    By hujef in forum General Questions
    Replies: 12
    Last Post: 23 Sep 2009, 06:19 PM
  2. Payflow Pro (new Module) problem with card validation
    By barco57 in forum Addon Payment Modules
    Replies: 5
    Last Post: 15 Sep 2009, 05:32 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg