New Zenner
- Join Date:
- Aug 2006
- Posts:
- 84
- Plugin Contributions:
- 0
Offline credit card module disallowed by some hosts?
I have my site configured with the credit card module to collect card details and process them on a manual EPOS terminal.
I have a dedicated SSL on my website.
I have been looking at changing hosts. TerraNetwork, one of your recommended companies, will not allow me to do this. They said:
I am afraid that we do not allow the use of Credit Card modules which store people's card details on our shared servers. This includes the CEON module for Zen Cart. It is inherently unsafe to store even part of the card
details in the database with the rest being sent by email. If a hacker did
gain access to your site then they would have access to the stored card
details and write themselves access to all outgoing emails - allowing them
to grab the remainder.
The Full SSL Certificate protects data whilst in transit by encrypting it.
However once that data is in the database, even if encrypted there, it is
delivered up to the Zen Cart admin panel in unencrypted format, and data
sent by email is not encrypted at all. That is why it is unsafe to store
card data on a shared server.
What other options do I have that won't add on to my evergrowing internet costs?