Results 1 to 7 of 7
  1. #1
    Join Date
    Sep 2006
    Posts
    75
    Plugin Contributions
    0

    Default credit card number encrypted

    I have a customer who wants the offline credit card module but is bent on having the digits stored on the database encrypted. is there a way to do that?

    many thanks for any help.

  2. #2
    Join Date
    Jun 2005
    Location
    Cumbria, UK
    Posts
    10,263
    Plugin Contributions
    3

    Default Re: credit card number encrypted

    Before you go down this road, there are several issues to consider, and you should (tactfully) advise your client of them.

    These include:-

    The nature of the Merchant Agreement your client has with their clearing bank/payment gateway.

    Legal constraints regarding the storage of sensitive data.

    Your webhost's policy on credit card data storage.

    The security of the server on which this data is to be stored.

    Compliance with secure data storage protocols.

    Level of SSL encryption and the additional security features offered by the Certificate Issuer.

    ... and a few more, I'm sure.
    20 years a Zencart User

  3. #3
    Join Date
    Sep 2006
    Posts
    75
    Plugin Contributions
    0

    Default Re: credit card number encrypted

    Sorry i should have been clearer. Not all the digit just the standard half of them that zencart stores anyway. They want those encrypted. i've worked out a patch that allows them to delete ithese digits from the admin after processing but can i encrypt it like the cvv is stored (if stored, i dont of course )?

  4. #4
    Join Date
    Jun 2003
    Posts
    33,715
    Plugin Contributions
    0

    Default Re: credit card number encrypted

    You could do that, but - encrypting them in the database will not allow you to read the numbers for processing. Decrypting them involves having a public and private key - not to mention the other things mentioned above.

    This is an old article but, you might want to have your client read it - http://www.networkworld.com/news/2005/061305-pci.html
    Please do not PM for support issues: a private solution doesn't benefit the community.

    Be careful with unsolicited advice via email or PM - Make sure the person you are talking to is a reliable source.

  5. #5
    Join Date
    Sep 2006
    Posts
    75
    Plugin Contributions
    0

    Default Re: credit card number encrypted

    I have the clients site on a standard shared hosting environment. I have HTTPS activated for all transfer points of sensitive data i can think of. Isn't this generally accepted as reasonably secure? While i might be abe to get around ecrypting the credit card surely there is lots of other info that I need to be worried about if the database is indeed compromised? surely that comes down to the security of the host?

    The client REALLY wants the credit card partial number in the database encrypted. what would you guys do in that situation? force them to sign up to a comprehensive payment gateway so it's not even an issue, or is it a legitamate request, Is the basic offline credit card mod generally accepted as secure and safe on the shared hosting environment i am on?

    As you can tell i'm a bit of a novice in regards to this creditcard processing and security. thanks for your answers and time

  6. #6
    Join Date
    Mar 2004
    Posts
    16,042
    Plugin Contributions
    5

    Default Re: credit card number encrypted

    the partial number in the DB is of no use to anyone anyway,
    so encrypting it, while doable, is not really needed.

    there is no more of the card number stored in the DB then there is on ANY sales receipt that you get anywhere

  7. #7
    Join Date
    Sep 2006
    Posts
    75
    Plugin Contributions
    0

    Default Re: credit card number encrypted

    If i was to appease this customer, how complicated is it to encrypt this feild like the cvv is (if stored)

 

 

Similar Threads

  1. Replies: 5
    Last Post: 29 Nov 2010, 06:28 AM
  2. My client wants to Store Credit Card numbers encrypted in the database on the server
    By infocom in forum Built-in Shipping and Payment Modules
    Replies: 14
    Last Post: 30 Mar 2008, 12:32 PM
  3. ALWAYS: The credit card number entered is invalid. Please check the number...
    By smoochinc in forum Built-in Shipping and Payment Modules
    Replies: 9
    Last Post: 14 Dec 2007, 10:15 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR