Hi,
You've gotten me wrong, there is no spat, I posted what I did for the protection of others, to advise them against the ramifications of the changes you suggested, I bear no ill feelings towards you.
No, you've said send the entire number in "in two e-mails", so if someone's e-mail account has been hacked the complete number can be constructed easily from the two e-mails.
Ceon Manual Card already uses a very unsecure process, that brings things to an even more unsecure level, simply to assuage a client's laziness.
Fair enough, I thought this was for you.
I'd advise you to revert the changes you made and advise your client that laziness is not a good enough excuse for mishandling customer's card details in this way.
Yes but Ceon manual Card preceeds that e-mail with an e-mail with the middle digits! :)
Glad you like it.
You can of course modify things to work whatever way you like but one person has since modified their Zen Cart, based on your suggestions, and may not have understood the ramifications of this, so I felt I had to post for other people's sake.
It is of course up to everyone individually to choose how they want to do things, we're all free thankfully!
It's best to be aware of the reasons the software works the way it does in the first place though!
To be honest, the suggested code I would make is to remove the entire credit card number from the order e-mail (as in remove the middle digits AND the last 4 digits! :) ).
Have a nice weekend!
All the best..
Conor
ceon



Reply With Quote
