Re: Secure Shopping PHP MySQL??
| From: | Thomas Deliduka | Date: | Thu, 07 Sep 2000 22:03:58 +0000 |
| Subject: | Re: Secure Shopping PHP MySQL?? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15784@lists.php.net to get a copy of this message | ||
On 9/7/00 5:46 PM this was written:
> I am using Sybase SQL-AnyWhere (via ODBC) for user authentication and I'm
> trying to make this as secure as possible. Is it possible to read the
> database over the web? How imporntant is it to encrypt the information in
> the database? The database is running on the server (Win NT - Apache).
It's extrememly important for the data to be encrypted in the database. I
don't know if you remember all those reports a year or so back that
mentioned all these online companies that had credit card information stored
and hackers got into their systems and stole credit card numbers. I am not
going to speculate on which sites because I can't remember and I don't want
to name a site it didn't happen to.
Either way the problem happened because:
1. not enough security on their db's
2. the cc information wasn't encrypted within the database so the numbers
were vulnerable.
Many poeple believe that just because the information is in a
password-protected database that it's secure and it's not. Encryption is
important, especially if you're reading the information across the web in a
PHP/ASP connection to the database.
--
Thomas Deliduka
IT Manager
-------------------------
New Eve Media
The Solution To Your Internet Angst
http://www.neweve.com/