Re: Secure Shopping PHP MySQL??

From: Date: Thu, 07 Sep 2000 23:35:07 +0000
Subject: Re: Secure Shopping PHP MySQL??
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-15798@lists.php.net to get a copy of this message
PHPlist wrote: > So let me get this straight...would I be correct in saying that if the site > is secure (SSL, https) and I am sending information via a form to a MySQL > database that the information is secure? > Because my limited understanding > of SSL is that the connection between the browser and the server is secure. true, and it works. There have been zero reported cases of information being stolen by attacking SSL. > But what about the information in the MySQL database? Are you sure you should be storing critical information in MySQL? MySQL is missing many features needed for robust data storage. > Then if I wanted the > customer to be able to go to a different area of the secure site to view the > Credit Card information using a browser and select statements, would that be > secure? This is where it gets tough for the web developer. You now have to make sure that people can only access *thier* information and not someone else's. This logic is typically implemented directly in PHP. You need to make sure that people can't do things like just change a parameter in a query string and get someone else's sensitive information, like what happened to the Australian Taxation Office Website recently. > I apologize for my newbie brain...I want to make sure that I am > understanding correctly. How can I keep this information secure in the > database? The best way to keep CC numbers secure is to *never* put them in a database in the first place. I'm guessing that you have gone a tiny bit past the design stage by now and can't easily fix this problem. Why do you need to store CC numbers? > Also Richard mentioned mcrypt. What is this and is this easy to use? It's a library for using (I assume) symmetric ciphers. I must warn you that it is very easy to use encryption *without* actually increasing overall security (but instead, just increasing a false sense of security). > My > problem is that I would like to stay away from using PGP/GnuPG if at all > possible. My customers can barely setup the email accounts I give them let > alone PGP. Trying to secure your database using encryption probably would not involve your customers needing to use PGP. security is not easy. I strongly recommend getting a good book on computer security and trying to develop that 'evil' cracker mindset that you need to do this stuff. -- Simon Edwards Animated Design, Melbourne http://www.animated.net.au/ Ph: (03) 98850990

« previous php.general (#15798) next »