RE: [PHP-DB] Credit Card Encryption

From: Date: Thu, 20 Dec 2007 04:59:02 +0000
Subject: RE: [PHP-DB] Credit Card Encryption
References: 1 2  Groups: php.db 
Request: Send a blank email to php-db+get-44440@lists.php.net to get a copy of this message
Gary, I take the view that I warn our customers about the dangers, and if really concerning ask for an indemnity or a very formal request for change. I really try to convince them of the correct path and keep any emails regarding the issues as backup Its a drag when you really have to consider how to cover your ass on this. Lawyers suck too. ;-P bastien> From: gwardell@gwsystems.co.il> To: bastien_k@hotmail.com> CC: bastien> php-db@lists.php.net> Subject: RE: [PHP-DB] Credit Card Encryption> Date: Wed, 19 Dec 2007 bastien> 23:21:52 -0500> > Hmm,> > This is kind of throwing a new twist on things.> > When bastien> it comes to liability, who is liable, the merchant running the system, the develper that created the bastien> system, or both?> > If the develper is included, would that be mitigated in that he created bastien> the system to the merchant's specifications?> > Also, in terms of the developer, would bastien> this be covered under errors and omissions insurance, or would they take the position that> the bastien> developer should have known better and was negligent in creating a non-compliant system leaving the bastien> developer on the hook for> damages?> > Gary> > > -----Original Message-----> bastien> > From: Bastien Koert [mailto:bastien_k@hotmail.com]> > Sent: Wed, December 19, 2007 11:02 bastien> PM> > To: Daniel Brown> > Cc: Keith Spiller; php-db@lists.php.net> > Subject: RE: bastien> [PHP-DB] Credit Card Encryption> >> >> >> > Dan,> >> > Normally bastien> I would completely agree, its our job to find those> > solutions. Unfortunately, the sector bastien> that my FT job deals> > with is retail and many of our clients are in this bind with> > bastien> PCI data. Hefty fines are charged to those not in compliance..> > The major CC companies are bastien> taking this so seriously and the> > ramifications are being felt in many IT shops. bastien> Compliance> > failure can lead to loss o privileges to accept CCs.> >> > Its gonna bastien> force us to be more creative in how we handle the> > data and create the applications that bastien> allow our clients to> > offer ecommerce, we will have to learn some business skills> > bastien> to make this happen. It may mean that its becomes more> > contractual in dealing with third bastien> parties, where the ecommece> > shop effects payment on behalf of the vendors. The OP may> bastien> > need to help his client work out a better way to manage the> > transactions between the bastien> related parties by finding ways to> > automate the various transactions and provide gateway bastien> access...> >> > I, too, like to eat... ;-P> >> > bastien> >> bastien> >> > > Date: Wed, 19 Dec 2007 17:21:57 -0500> From:> > parasane@gmail.com> bastien> To: bastien_k@hotmail.com> Subject: Re:> > [PHP-DB] Credit Card Encryption> CC: bastien> larentium@hosthive.com;> > php-db@lists.php.net> > On Dec 19, 2007 4:45 PM, Bastien> bastien> > Koert <bastien_k@hotmail.com> wrote:> >> > Nope, I still> > would not bastien> recommmend it. The only place the CC data should> > travel to is the payment gateway. Anything bastien> else is a security> > risk. Why does your client process by hand? They should be> > bastien> using a payment gateway.> > That's true, Bastien, but if for> > whatever reason bastien> it's not an> option for them, what? Tell them> > it's tough cookies and bastien> they're SOL?> > Our job as programmers> > - especially freelance - is to make bastien> things> happen as safely> > and securely as we can, but as a bottom line, make it>> bastien> > happen. I'm sure we (most of us) take the responsibility to>> > discourage a bastien> client from making such choices, and to educate> > them on> alternatives that are better bastien> for their interests,> > but still - at the> end of the day, we're still just code> bastien> > monkeys. We're expected to> build what the client needs, or> > else they'll bastien> find someone else to do> it for them.> > And I> > don't really like to go bastien> hungry. ;-)> > -- > Daniel P. Brown>> > [Phone Numbers Go Here!]> [They're bastien> Hidden From View!]> > If> > at first you don't succeed, stick to what you know best bastien> so> > that you> can make enough money to pay someone else to do it for you.> > bastien> _________________________________________________________________> > Exercise your brain! Try bastien> Flexicon!> > bastien> http://puzzles.sympatico.msn.ca/chicktionary/index.html?icid=htmlsig> bastien> _________________________________________________________________ Exercise your brain! Try Flexicon! http://puzzles.sympatico.msn.ca/chicktionary/index.html?icid=htmlsig

« previous php.db (#44440) next »