RE: [PHP-DB] Credit Card Encryption
| From: | Bastien Koert | Date: | Wed, 19 Dec 2007 21:45:11 +0000 |
| Subject: | RE: [PHP-DB] Credit Card Encryption | ||
| References: | 1 2 3 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-44436@lists.php.net to get a copy of this message | ||
Nope, I still would not recommmend it. The only place the CC data should travel to is the payment
gateway. Anything else is a security risk. Why does your client process by hand? They should be
using a payment gateway.
bastien> From: larentium@hosthive.com> To: bastien_k@hotmail.com; php-db@lists.php.net>
bastien> Subject: Re: [PHP-DB] Credit Card Encryption> Date: Wed, 19 Dec 2007 00:41:36 -0700> > Ok
bastien> I've done some research and some thinking. What about storing orders in > the database
bastien> (product info and customer info) and then using GnuPG or PGP to > send the credit card info to
bastien> the merchant? This way the credit card > information is not stored on the server or in the
bastien> database but only in > printed format by the merchant. Since my client processes all of the
bastien> credit > card orders by hand this seems like an ideal solution.> > What is more, the order
bastien> and customer info do not need to be present in the > encrypted emails. That way the email does
bastien> not contain a customer name, but > only an order id (which could even be a unique and hidden
bastien> value stored via > AES in the mysql db).> > What are your thoughts?> > Keith> >
bastien> ----- Original Message ----- > From: "Bastien Koert" <bastien_k@hotmail.com>>
bastien> To: "Keith Spiller" <larentium@hosthive.com>; <php-db@lists.php.net>> Sent:
bastien> Tuesday, December 18, 2007 9:41 PM> Subject: RE: [PHP-DB] Credit Card Encryption> > >
bastien> > Think very carefully about what you want to do here. PCI (payment card > industry) has
bastien> radically changed the rules about how CC data is stored in a > networked environment. If your
bastien> data environment is shared (shared web > hosting), don't even think about it. There are a
bastien> large number of rules that > you need to follow to make your data systems PCI compliant [ >
bastien> http://www.pcicomplianceguide.org/ ] and they are not easy to
bastien> follow.. Things > like strong encryption, code audits by qualified third parties etc.> > If
bastien> you absolutely need to store the data (many of my large clients do this):> 1. the database server
bastien> should not be web facing, nor accessible internally > by the web servers> 2. the access
bastien> (physical and electronic) should be extremely limited> 3. the facility that holds the data should
bastien> be hardened with limited > controlled access> 4. provide a cross reference number to the CC
bastien> that other applications can > use to replace the CC number> > If you are storing
bastien> transactional data, just store the confirmation number > that is returned by the payment gateway
bastien> that you use. Let the payment > gateway assume the risks of handling the data, its what they get
bastien> paid for. > If the data is for re-occurring payments, let the payment gateway handle it, >
bastien> many support these kinds of payments.> > Bastien> > From: larentium@hosthive.com> To:
bastien> php-db@lists.php.net> CC: > > larentium@hosthive.com> Date: Tue, 18 Dec 2007 18:20:08
bastien> -0700> Subject: > > [PHP-DB] Credit Card Encryption> > Hi Everyone,> > I'm
bastien> trying to determine > > the best method to store credit card numbers in a > mysql database.
bastien> As yet > > I have been unable to determine whether I should use > MySQL AES, DES or a >
bastien> > PHP encryption method. I would greatly appreciate any > advice you guys > > could
bastien> offer.> > Thanks.> > Keith > > -- > PHP Database Mailing List > >
bastien> (http://www.php.net/)> To unsubscribe, visit: > >
bastien> http://www.php.net/unsub.php>>
bastien> _________________________________________________________________> Discover new ways to stay in
bastien> touch with Windows Live! Visit the City @ Live > today!>
bastien> http://getyourliveid.ca/?icid=LIVEIDENCA006 >
_________________________________________________________________
Introducing the City @ Live! Take a tour!
http://getyourliveid.ca/?icid=LIVEIDENCA006