RE: [PHP-DB] Credit Card Encryption
| From: | Bastien Koert | Date: | Thu, 20 Dec 2007 04:59:02 +0000 |
| Subject: | RE: [PHP-DB] Credit Card Encryption | ||
| References: | 1 2 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-44440@lists.php.net to get a copy of this message | ||
Gary,
I take the view that I warn our customers about the dangers, and if really concerning ask for an
indemnity or a very formal request for change. I really try to convince them of the correct path and
keep any emails regarding the issues as backup
Its a drag when you really have to consider how to cover your ass on this. Lawyers suck too. ;-P
bastien> From: gwardell@gwsystems.co.il> To: bastien_k@hotmail.com> CC:
bastien> php-db@lists.php.net> Subject: RE: [PHP-DB] Credit Card Encryption> Date: Wed, 19 Dec 2007
bastien> 23:21:52 -0500> > Hmm,> > This is kind of throwing a new twist on things.> > When
bastien> it comes to liability, who is liable, the merchant running the system, the develper that created the
bastien> system, or both?> > If the develper is included, would that be mitigated in that he created
bastien> the system to the merchant's specifications?> > Also, in terms of the developer, would
bastien> this be covered under errors and omissions insurance, or would they take the position that> the
bastien> developer should have known better and was negligent in creating a non-compliant system leaving the
bastien> developer on the hook for> damages?> > Gary> > > -----Original Message----->
bastien> > From: Bastien Koert [mailto:bastien_k@hotmail.com]> > Sent: Wed, December 19, 2007 11:02
bastien> PM> > To: Daniel Brown> > Cc: Keith Spiller; php-db@lists.php.net> > Subject: RE:
bastien> [PHP-DB] Credit Card Encryption> >> >> >> > Dan,> >> > Normally
bastien> I would completely agree, its our job to find those> > solutions. Unfortunately, the sector
bastien> that my FT job deals> > with is retail and many of our clients are in this bind with> >
bastien> PCI data. Hefty fines are charged to those not in compliance..> > The major CC companies are
bastien> taking this so seriously and the> > ramifications are being felt in many IT shops.
bastien> Compliance> > failure can lead to loss o privileges to accept CCs.> >> > Its gonna
bastien> force us to be more creative in how we handle the> > data and create the applications that
bastien> allow our clients to> > offer ecommerce, we will have to learn some business skills> >
bastien> to make this happen. It may mean that its becomes more> > contractual in dealing with third
bastien> parties, where the ecommece> > shop effects payment on behalf of the vendors. The OP may>
bastien> > need to help his client work out a better way to manage the> > transactions between the
bastien> related parties by finding ways to> > automate the various transactions and provide gateway
bastien> access...> >> > I, too, like to eat... ;-P> >> > bastien> >>
bastien> >> > > Date: Wed, 19 Dec 2007 17:21:57 -0500> From:> > parasane@gmail.com>
bastien> To: bastien_k@hotmail.com> Subject: Re:> > [PHP-DB] Credit Card Encryption> CC:
bastien> larentium@hosthive.com;> > php-db@lists.php.net> > On Dec 19, 2007 4:45 PM, Bastien>
bastien> > Koert <bastien_k@hotmail.com> wrote:> >> > Nope, I still> > would not
bastien> recommmend it. The only place the CC data should> > travel to is the payment gateway. Anything
bastien> else is a security> > risk. Why does your client process by hand? They should be> >
bastien> using a payment gateway.> > That's true, Bastien, but if for> > whatever reason
bastien> it's not an> option for them, what? Tell them> > it's tough cookies and
bastien> they're SOL?> > Our job as programmers> > - especially freelance - is to make
bastien> things> happen as safely> > and securely as we can, but as a bottom line, make it>>
bastien> > happen. I'm sure we (most of us) take the responsibility to>> > discourage a
bastien> client from making such choices, and to educate> > them on> alternatives that are better
bastien> for their interests,> > but still - at the> end of the day, we're still just code>
bastien> > monkeys. We're expected to> build what the client needs, or> > else they'll
bastien> find someone else to do> it for them.> > And I> > don't really like to go
bastien> hungry. ;-)> > -- > Daniel P. Brown>> > [Phone Numbers Go Here!]> [They're
bastien> Hidden From View!]> > If> > at first you don't succeed, stick to what you know best
bastien> so> > that you> can make enough money to pay someone else to do it for you.> >
bastien> _________________________________________________________________> > Exercise your brain! Try
bastien> Flexicon!> >
bastien> http://puzzles.sympatico.msn.ca/chicktionary/index.html?icid=htmlsig>
bastien>
_________________________________________________________________
Exercise your brain! Try Flexicon!
http://puzzles.sympatico.msn.ca/chicktionary/index.html?icid=htmlsig