Results 1 to 4 of 4
  1. #1
    Join Date
    Jan 2004
    Posts
    15
    Plugin Contributions
    0

    Default Offline Credit Card Orders

    I do not see the security of the offline cc process where you enter an email adress and two emails are sent one with first 4 and last 4 and the other with the middle 8. But you can't view the whole thing in an encrypted admin module.

    Way easier to hack intop un unencrypted email account than to hack into the encrypted admin module.

  2. #2
    Join Date
    Jan 2004
    Posts
    15
    Plugin Contributions
    0

    Default Re: Offline Credit Card Orders

    The more I think about this the less sense it makes. I get an order confirmation with first 4 and last 4 with all the customer info, what they order their billing and shipping addresses and then I get a second email with the order number and the middle 8 digits.

    Sending any of this information to an email address is very bad, let alone all of the information. But somehow it is not allowable to view the whole creditcard number in a secure admin panel.

    What genius thought of this?

  3. #3
    Join Date
    Jan 2004
    Posts
    15
    Plugin Contributions
    0

    Default Re: Offline Credit Card Orders

    Here are the instruction for setting up and the explanation of why:

    https://www.zen-cart.com/tutorials/index.php?article=67

    How is sending this info out in email is an acceptable alternative?

  4. #4
    Join Date
    Jan 2004
    Posts
    66,419
    Blog Entries
    7
    Plugin Contributions
    81

    Default Re: Offline Credit Card Orders

    Good points. So ... don't use it then! It's not suitable for everyone, and in my opinion should be used by nobody.

    If you're not happy with the security of that method, simply use another method that suits your needs and comfort levels better. There are many great gateway services out there for you to use, which offer much greater security than something that gives you the number to process yourself.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

 

 

Similar Threads

  1. Offline credit card for 1.3.9?
    By imfsub12 in forum Upgrading from 1.3.x to 1.3.9
    Replies: 2
    Last Post: 12 Feb 2011, 12:47 AM
  2. Offline Credit Card Processing
    By JTheed in forum Upgrading from 1.3.x to 1.3.9
    Replies: 7
    Last Post: 19 Apr 2010, 05:58 PM
  3. Offline Credit Card Processing
    By andy86 in forum Built-in Shipping and Payment Modules
    Replies: 3
    Last Post: 22 Oct 2009, 10:07 AM
  4. Credit card offline process
    By alvalong in forum Built-in Shipping and Payment Modules
    Replies: 1
    Last Post: 30 Apr 2008, 04:56 PM
  5. Offline Credit Card
    By the_ancient in forum General Questions
    Replies: 2
    Last Post: 19 Mar 2007, 07:12 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR