Re: Secure Shopping PHP MySQL??
| From: | Bjorn Andre Lie | Date: | Thu, 07 Sep 2000 21:46:20 +0000 |
| Subject: | Re: Secure Shopping PHP MySQL?? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15782@lists.php.net to get a copy of this message | ||
I am using Sybase SQL-AnyWhere (via ODBC) for user authentication and I'm trying to make this as secure as possible. Is it possible to read the database over the web? How imporntant is it to encrypt the information in the database? The database is running on the server (Win NT - Apache).
Regards,
Bjørn André Lie
IT-Manager
At 13:20 07.09.00 -0400, you wrote:
The information exchanged between your web server/php app and the MySQL database happens on the same machine (normally but not always) and so that information is secure. If it happens on different machines you could have a SAN (Storage Area Network) setup that's not external to the world that can exchange the information. Either way, that normally is secure. Where the insecurity comes into play is the data you store in the database itself. You should encrypt the CC information that you store, if you store it. That can be done by using an encode() function in mysql with a key or some other way I use a simple function that changes the numbers around that's crackable but it would take a while todo so. Perhaps I need to do it a different way but that's what I knew at the time. Anyway. If the sensitive information in the database isn't encrypted then there's a possibility (if someone gets the username and pass for the db) that someone could get that information. On 9/7/00 12:36 PM this was written: So let me get this straight...would I be correct in saying that if the site is secure (SSL, https) and I am sending information via a form to a MySQL database that the information is secure? Because my limited understanding of SSL is that the connection between the browser and the server is secure. But what about the information in the MySQL database? Then if I wanted the customer to be able to go to a different area of the secure site to view the Credit Card information using a browser and select statements, would that be secure? I apologize for my newbie brain...I want to make sure that I am understanding correctly. How can I keep this information secure in the database? -- Thomas Deliduka IT Manager-------------------------New Eve Media The Solution To Your Internet Angst http://www.neweve.com/ -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net