Results 1 to 3 of 3
  1. #1
    Join Date
    Dec 2007
    Location
    New Jersey
    Posts
    76
    Plugin Contributions
    0

    Default storing cc numbers, pci compliance, and CIM oh my

    Hi all you Brilliant Zenners,

    I have a doozy of a question for you. A customer wants to store credit cart info online. and be compliant with the new standards.
    so, in order to do this, I was thinking:

    using AIM module
    1. drop out the full number before it is even sent to the payment gateway
    2. put in a sql table
    3. encrypt it with mod 5 hash
    4. decrypt it on the checkout and customer information screens

    OR and this is probably smarter:

    has anyone out there developed a module that will work with CIM? I am reading up on this now, and authorize dot net is really pushing this as the best way to store cards. if anyone has written this mod, please PM me. I'm interested...

    any thoughts, tips, suggestions would be very useful.
    hmmn. really?

  2. #2
    Join Date
    Mar 2004
    Posts
    16,042
    Plugin Contributions
    5

    Default Re: storing cc numbers, pci compliance, and CIM oh my

    Explain to your client that storing CC numbers is a headache that is really NOT worth it,

    IF they are going through the gateway then there is NO need for them to ever store cc numbers.........

    I see a headache and it says excedrin ALL over it

  3. #3
    Join Date
    Dec 2007
    Location
    New Jersey
    Posts
    76
    Plugin Contributions
    0

    Default Re: storing cc numbers, pci compliance, and CIM oh my

    I agree with you. I am really leaning away from it. CIM is a method authorize dot net is pushing, and I think it may be worth the 20 bucks a month for their piece of mind.

    that being said, anyone out there know about CIM yet? its fairly new. here's what the authorize dot net website says:

    Customer Information Manager (CIM) – API Guide
    The Authorize.Net Customer Information Manager (CIM) allows merchants to create customer profiles that are stored on Authorize.Net’s secure servers. By providing quick access to stored customer information, CIM is ideal for businesses that:

    blah, blah, stuff that applies to me
    ~Are concerned with PCI compliance.
    ~Want to provide returning customers with the convenience of not having to re-enter personal data.

    The CIM API supports integration with a Web site payment form or a proprietary business application. The profiles, which include payment and shipping information, can then be referenced in future transactions, eliminating steps in the transaction process for repeat customers and potentially increasing customer loyalty.

    there is an XML and a SOAP api guideline. i guess i'm gonna have to roll up my sleeves and just do this. BUT I'm going to wait and see if someone else has. again, PM me, I am totally interested in connecting with you if you've a way around this already...
    hmmn. really?

 

 

Similar Threads

  1. MSQL and PHP update - PCI Compliance
    By wapnoj in forum General Questions
    Replies: 0
    Last Post: 3 Aug 2010, 03:06 AM
  2. PayPal Payments Pro and PCI Compliance Help
    By reg22 in forum PayPal Website Payments Pro support
    Replies: 7
    Last Post: 26 May 2010, 03:28 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR