Zen Cart Logo
Forums / Built-in Shipping and Payment Modules / Is CC info seperated and sent by email secure?

Is CC info seperated and sent by email secure?

Locked

Views: 803

Results 1 to 5 of 5
This thread is locked. New replies are disabled.
24 Aug 2009, 8:59 PM
#1
pillowlady avatar

pillowlady

New Zenner

Join Date:
Aug 2009
Posts:
3
Plugin Contributions:
0

Is CC info seperated and sent by email secure?

Finishing up my PCI compliance and am wondering:
I Am using offline processing with Zencart with SSL, is the extra CC info sent to me by email (comes in 2 seperate email) secure???

24 Aug 2009, 9:32 PM
#2
kobra avatar

kobra

Black Belt

Join Date:
Aug 2005
Location:
Arizona
Posts:
31,500
Plugin Contributions:
4

Re: Is CC info seperated and sent by email secure?

Finishing up my PCI compliance and am wondering:
I Am using offline processing with Zencart with SSL, is the extra CC info sent to me by email (comes in 2 seperate email) secure???
No!! It is not sent encrypted nor secure

25 Aug 2009, 12:54 AM
#3
pillowlady avatar

pillowlady

New Zenner

Join Date:
Aug 2009
Posts:
3
Plugin Contributions:
0

Re: Is CC info seperated and sent by email secure?

If email is a non-secure way to send additional CC info (for offline processing), then how can you access all the CC info needed, securely through Zencart?

Peacefull Pillows
Handcrafted Organic Comfort

25 Aug 2009, 1:22 AM
#4
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Is CC info seperated and sent by email secure?

Sending both emails to the same address is certainly not a secure approach.

You'll need to ask your PCI person whether they will pass you if the credit card digits are supplied to you in separate emails. I've seen many people pass compliance by sending the middle digits to an email address that's stored on another domain on another server separate from the one where your order confirmation emails are sent.
And then of course deleting those emails once you've processed the orders.

In the simplest sense sending the middle digits via email, and leaving the outer digits on the server, is secure. But having 2 emails sent to the same place containing the sum total of all digits is ... dangerous, for the reasons kobra mentioned.

But ... a much safer and secure approach is to use a payment gateway service that processes the card in real time. That also gives the customer immediate access to whatever they've purchased ... which is important if you're selling digital goods. There's the added cost of a monthly fee for live processing, which can be a minor deterrent for some in the early stages of business, or so some say. It's a lot less work to have it done live than to have to process them manually later, especially if the card is declined for some reason ... the gateway would have caught that immediately and the customer would have to sort it out, rather than you having to contact them and work out other arrangements or try other cards etc etc etc.

HTH

26 Aug 2009, 1:53 PM
#5
pillowlady avatar

pillowlady

New Zenner

Join Date:
Aug 2009
Posts:
3
Plugin Contributions:
0

Re: Is CC info seperated and sent by email secure?

Thanks for all the great information, I really appreciate it! Where would we be without folks like you, keeping us straight.

I will set things up the way you suggested, having CC info come to another separate domain on separate server, until I am ready for a payment gateway.

Peacefull Pillows
Handcrafted Organic Comfort