RE: [PHP-DB] Credit Card Encryption

From: Date: Wed, 19 Dec 2007 21:45:11 +0000
Subject: RE: [PHP-DB] Credit Card Encryption
References: 1 2 3  Groups: php.db 
Request: Send a blank email to php-db+get-44436@lists.php.net to get a copy of this message
Nope, I still would not recommmend it. The only place the CC data should travel to is the payment gateway. Anything else is a security risk. Why does your client process by hand? They should be using a payment gateway. bastien> From: larentium@hosthive.com> To: bastien_k@hotmail.com; php-db@lists.php.net> bastien> Subject: Re: [PHP-DB] Credit Card Encryption> Date: Wed, 19 Dec 2007 00:41:36 -0700> > Ok bastien> I've done some research and some thinking. What about storing orders in > the database bastien> (product info and customer info) and then using GnuPG or PGP to > send the credit card info to bastien> the merchant? This way the credit card > information is not stored on the server or in the bastien> database but only in > printed format by the merchant. Since my client processes all of the bastien> credit > card orders by hand this seems like an ideal solution.> > What is more, the order bastien> and customer info do not need to be present in the > encrypted emails. That way the email does bastien> not contain a customer name, but > only an order id (which could even be a unique and hidden bastien> value stored via > AES in the mysql db).> > What are your thoughts?> > Keith> > bastien> ----- Original Message ----- > From: "Bastien Koert" <bastien_k@hotmail.com>> bastien> To: "Keith Spiller" <larentium@hosthive.com>; <php-db@lists.php.net>> Sent: bastien> Tuesday, December 18, 2007 9:41 PM> Subject: RE: [PHP-DB] Credit Card Encryption> > > bastien> > Think very carefully about what you want to do here. PCI (payment card > industry) has bastien> radically changed the rules about how CC data is stored in a > networked environment. If your bastien> data environment is shared (shared web > hosting), don't even think about it. There are a bastien> large number of rules that > you need to follow to make your data systems PCI compliant [ > bastien> http://www.pcicomplianceguide.org/ ] and they are not easy to bastien> follow.. Things > like strong encryption, code audits by qualified third parties etc.> > If bastien> you absolutely need to store the data (many of my large clients do this):> 1. the database server bastien> should not be web facing, nor accessible internally > by the web servers> 2. the access bastien> (physical and electronic) should be extremely limited> 3. the facility that holds the data should bastien> be hardened with limited > controlled access> 4. provide a cross reference number to the CC bastien> that other applications can > use to replace the CC number> > If you are storing bastien> transactional data, just store the confirmation number > that is returned by the payment gateway bastien> that you use. Let the payment > gateway assume the risks of handling the data, its what they get bastien> paid for. > If the data is for re-occurring payments, let the payment gateway handle it, > bastien> many support these kinds of payments.> > Bastien> > From: larentium@hosthive.com> To: bastien> php-db@lists.php.net> CC: > > larentium@hosthive.com> Date: Tue, 18 Dec 2007 18:20:08 bastien> -0700> Subject: > > [PHP-DB] Credit Card Encryption> > Hi Everyone,> > I'm bastien> trying to determine > > the best method to store credit card numbers in a > mysql database. bastien> As yet > > I have been unable to determine whether I should use > MySQL AES, DES or a > bastien> > PHP encryption method. I would greatly appreciate any > advice you guys > > could bastien> offer.> > Thanks.> > Keith > > -- > PHP Database Mailing List > > bastien> (http://www.php.net/)> To unsubscribe, visit: > > bastien> http://www.php.net/unsub.php>> bastien> _________________________________________________________________> Discover new ways to stay in bastien> touch with Windows Live! Visit the City @ Live > today!> bastien> http://getyourliveid.ca/?icid=LIVEIDENCA006 > _________________________________________________________________ Introducing the City @ Live! Take a tour! http://getyourliveid.ca/?icid=LIVEIDENCA006

« previous php.db (#44436) next »