Re: Secure Shopping PHP MySQL??
| From: | PHPlist | Date: | Thu, 07 Sep 2000 16:36:21 +0000 |
| Subject: | Re: Secure Shopping PHP MySQL?? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15743@lists.php.net to get a copy of this message | ||
So let me get this straight...would I be correct in saying that if the site
is secure (SSL, https) and I am sending information via a form to a MySQL
database that the information is secure? Because my limited understanding
of SSL is that the connection between the browser and the server is secure.
But what about the information in the MySQL database? Then if I wanted the
customer to be able to go to a different area of the secure site to view the
Credit Card information using a browser and select statements, would that be
secure? I apologize for my newbie brain...I want to make sure that I am
understanding correctly. How can I keep this information secure in the
database?
Also Richard mentioned mcrypt. What is this and is this easy to use? My
problem is that I would like to stay away from using PGP/GnuPG if at all
possible. My customers can barely setup the email accounts I give them let
alone PGP.
TIA,
Scott
----- Original Message -----
From: "Brian Rue" <dwjw@quixnet.net>
To: "'Richard Lynch'" <richard@zend.com>;
<php-general@lists.php.net>
Sent: Sunday, May 07, 2000 5:40 PM
Subject: RE: [PHP] Secure Shopping PHP MySQL??
> I would also suggest using a secure program to connect to MySQL, or the
whole thing is pointless. OpenSSH is a good one (www.openssh.com)
>
> -----Original Message-----
> From: Richard Lynch [SMTP:richard@zend.com]
> Sent: Tuesday, September 05, 2000 10:24 PM
> To: php-general@lists.php.net
> Subject: Re: [PHP] Secure Shopping PHP MySQL??
>
> In article <01b901c01784$33e5e440$aa23eec7@ncelec.com>,
> phplist@webbcite.com ("PHPlist") wrote:
>
> > I am trying to put together a small site with a few items that can be
> > ordered. I have a secure certificate (SSL/https) that will house the
site.
> > I can not afford to pay the pricing of PGP for the server to encrypt
form
> > mail. I have not been able to get GnuPG to send an encrypted email
message
> > to a remote Windoz PGP client to be viewed. It doesn't sound like there
is
> > much support for Windoz products under GnuPG.
>
> Last I checked, gpg worked just fine under Windows, if you didn't mind
> using MS-DOS to talk to it... But it's been awhile since I've tried it...
>
> Oooh. I think you also have to dink around with newline conversion, or
> make sure it doesn't happen or something. But it did work, once upon a
> time.
>
> There's definitely some threads on gpg in the old mailing list archives
> and how to use it to send the e-mail.
>
> I set up a similar system for a guy once, 'cuz he already had a kerchunker
> (okay, so it's a card-swiper these days) and didn't want to pay an extra
> 5% to the ISP.
>
> > Another option that I was thinking of was using PHP3 and MySQL. I would
> > like the customer to order online via the secure connection and have the
> > ordering information stored in a MySQL database. The customer could
then go
> > to a secure web page and view the order information and process the
order
> > manually.
> >
> > Is this possible? Any security concerns with doing it this way?
>
> How secure is the MySQL database?
> Unless it's
> (A) running on the same box as SSL, and *NOT* available to any other box,
or
> (B) running on a different box, but *ONLY* available to the SSL box
> you've got problems if you are going to be storing sensitive data in the
> database. If you process the credit cards in real-time, and only store
> the shipping info and what the client ought to be sending, that would be
> okay.
>
> > Does anyone have any other *inexpensive* solutions to e-commerce using
SSL,
> > PHP, MySQL?
>
> CCNow takes like 9%, and doing it yourself through a card-swipe, unless
> you have big volume, the credit card companies are gonna take 4%, so the
> difference is not that big...
>
> CyberCash (et al) may or may not be supported by your web-host, so they
> may have an account you can piggy-back on for little or nothing.
>
> I've been down the path you're on, and I gotta say that having an ISP set
> up the SSL and CyberCash stuff for me and paying him 10% was way less
> frustrating than futzing with gpg setup and then training the computer
> illiterate to use gpg.
> --
> Richard Lynch | If this was worth $$$ to you, buy a CD
> US Customer Support Director | from one of the artists listed here:
> Zend Technologies USA | http://www.L-I-E.com/artists.htm
> http://www.zend.com | (this has nothing to do with
> Zend, duh!)