Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - how to use SSL ??
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

how to use SSL ??

 Post Reply Post Reply Page  <1234>
Author
the boss View Drop Down
Senior Member
Senior Member
Avatar

Joined: 19 January 2003
Location: Saudi Arabia
Status: Offline
Points: 1727
Post Options Post Options   Thanks (0) Thanks(0)   Quote the boss Quote  Post ReplyReply Direct Link To This Post Posted: 11 December 2003 at 2:52am

same indivisual doesnt make onlines purchaes everyday from ur site nither any near frequently....so why fell in mess by storing CC number.. just let the user enter it each time they make a purchase. bet the idential user just makes a purches once in a year from ur site..

BTW...CC number in email.. thats the most silly thing to think off



Edited by the boss

Back to Top
dizzyfunk View Drop Down
Newbie
Newbie


Joined: 12 September 2003
Location: United Kingdom
Status: Offline
Points: 17
Post Options Post Options   Thanks (0) Thanks(0)   Quote dizzyfunk Quote  Post ReplyReply Direct Link To This Post Posted: 11 December 2003 at 3:02am

ok then - funny man!! i'm asking for help here and you're just taking the piss?!?!?

what do i do then???

my customer wants to process the credit card transaction himself thru his point of sale machine in his shop. he needs to get teh cc number from the website how can he do it then?

you're saying not to store the cc in the DB. so, being obviously not as knowledgable as your greatness(!!!) i suggested email.. look - i made it clear at the beginning of this post that i don't know.. that's why i'm posting for help..

Back to Top
dizzyfunk View Drop Down
Newbie
Newbie


Joined: 12 September 2003
Location: United Kingdom
Status: Offline
Points: 17
Post Options Post Options   Thanks (0) Thanks(0)   Quote dizzyfunk Quote  Post ReplyReply Direct Link To This Post Posted: 11 December 2003 at 3:03am

someone mentioned visa requirements - do you have a link?

i've looked on the visa site and can't find it

 

thanks in advnace

 

Back to Top
ljamal View Drop Down
Mod Builder Group
Mod Builder Group


Joined: 16 April 2003
Status: Offline
Points: 888
Post Options Post Options   Thanks (0) Thanks(0)   Quote ljamal Quote  Post ReplyReply Direct Link To This Post Posted: 11 December 2003 at 4:37am
Back to Top
Mart View Drop Down
Senior Member
Senior Member
Avatar

Joined: 30 November 2002
Status: Offline
Points: 2304
Post Options Post Options   Thanks (0) Thanks(0)   Quote Mart Quote  Post ReplyReply Direct Link To This Post Posted: 11 December 2003 at 9:21am
Emails can be read at smtp servers in dump directorys. Unless you send it encrypted i cant even think where to start my critism you should also put your login page in an ssl dir. because if someone nicks their username and password they could login and go on a  shopping spree
Back to Top
dpyers View Drop Down
Senior Member
Senior Member


Joined: 12 May 2003
Status: Offline
Points: 3937
Post Options Post Options   Thanks (0) Thanks(0)   Quote dpyers Quote  Post ReplyReply Direct Link To This Post Posted: 11 December 2003 at 4:39pm

You can also encrypt the email as well The server and the recipient each have a key. I'd use a VPN between the server and the customer in this case, but you need to be aware of where the email may be stored before the customer gets it and secure that area as well. some *nix distributions support an encrypted file system. Also, don't forget that most hosts make backups that aren't anywhere near as secure as the online disks.

The customers PC in this instance would also require some sort of physical and technological security.

This whole scenario is why I drop cash every year on business insurance that covers errors and omissions. CC processing isn't something you want to get into until you've done a lot of research.

The bottom line is that you have to weigh your potential risk (lawsuit from the customer to recover any losses) against the cost and effort of offloading that risk either through a larger investment in security, insurance. or by contracting with a third party cc handler.


Lead me not into temptation... I know the short cut, follow me.
Back to Top
Gullanian View Drop Down
Senior Member
Senior Member
Avatar

Joined: 04 January 2002
Location: England
Status: Offline
Points: 4373
Post Options Post Options   Thanks (0) Thanks(0)   Quote Gullanian Quote  Post ReplyReply Direct Link To This Post Posted: 11 December 2003 at 5:20pm
Just hire a third party CC processor
Back to Top
God_Struth View Drop Down
Senior Member
Senior Member
Avatar

Joined: 07 August 2003
Location: United Kingdom
Status: Offline
Points: 218
Post Options Post Options   Thanks (0) Thanks(0)   Quote God_Struth Quote  Post ReplyReply Direct Link To This Post Posted: 11 December 2003 at 5:41pm
Originally posted by dizzyfunk dizzyfunk wrote:

i suggested email.. look - i made it clear at the beginning of this post that i don't know.. that's why i'm posting for help..




Don't use email, plain and simple. Even trying to encrypt etc is not a fail safe way to go. Rule this out and ensure your customer knows its not a viable option.

What sort of databse are you going/thinking of using?

If its access then you would have to ensure its in a secure directory, maybe also password protect the database itself.

If its SQL server then that may well be a different story all together as its far more secure.

Either way, the only other files you need to protect are the login and the processing + collection pages, everything else can be outside the https:.

(Do you have a certificate to enable https: on your server/site? Verisign or Thawte for the digital cert.. )


My personal preference would be to use a third party like Worldpay or paypal unless it was essential to do it myself.

The main reason being, as has already been mentioned, is the possibility of fraud. YOU can/could/would be held liable if your 'system' had a flaw and someone got the CC numbers, you could be talking a hell of a lot of money if you got stung.


The easy way out would be to tell the customer that you don't do that field of web technology, tell them its a specialist area requiring someone with comprehensive knowledge of Secure Web Services.

Course I am joking, but unless you kow what your doing things could get sticky if you feck things up
"I'm only trying to help......"
Back to Top
 Post Reply Post Reply Page  <1234>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.