Beginner Programming
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsOtherBeginner Programming

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old April 28th, 2003, 10:11 AM
rob46 rob46 is offline
A Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2002
Location: dk
Posts: 267 rob46 User rank is Corporal (100 - 500 Reputation Level)rob46 User rank is Corporal (100 - 500 Reputation Level)rob46 User rank is Corporal (100 - 500 Reputation Level)rob46 User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 1 Day 17 h 6 m 48 sec
Reputation Power: 10
Credit Card Question

Hi - I'm looking for a bit of advice with an e-commerce problem.

Ok, suppose the user has gone to a checkout on a site. All the order details are done, they just type in some credit card details. Once they click Submit - they should get an order conformation and go back to the home page or something similar.
My question is what to do with the CC details. If the person already has CC processing equipment then they are not going to want to pay for some "Secure Process Service".
Is it ok to send the order / CC details by encrypted email? I wouldn't have thought storing them on a db would be wise.

Any suggestions?
Thanks

Reply With Quote
  #2  
Old April 28th, 2003, 10:19 AM
a.koepke's Avatar
a.koepke a.koepke is offline
Second highest poster :p
Dev Shed God 5th Plane (7000 - 7499 posts)
 
Join Date: Jul 2001
Posts: 7,323 a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 8 h 13 m 55 sec
Reputation Power: 27
Well if they already have a merchant account with a bank you may find the bank can provide them with a cheap online payment solution that links into their existing account.

Encrypted emails is one way of doing things, the other way would be to PGP them and save encrypted version in DB (GnuPG http://www.gnupg.org/). Then open page that displays them and decrypt them using the private key. That would be the most secure method.
__________________
- Andreas Koepke

Koepke Photography


Reply With Quote
  #3  
Old April 28th, 2003, 10:28 AM
rod k rod k is offline
Apprentice Deity
Dev Shed Loyal (3000 - 3499 posts)
 
Join Date: Jul 1999
Location: Niagara Falls (On the wrong side of the gorge)
Posts: 3,237 rod k User rank is Private First Class (20 - 50 Reputation Level)rod k User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 4 m 8 sec
Reputation Power: 13
Send a message via AIM to rod k
Andreas, maybe I'm misunderstanding what you are saying here

Quote:
open page that displays them and decrypt them using the private key


but this would mean the private key would have to be on the server, which isn't secure.
__________________
FSBO (For Sale By Owner) Realty

Reply With Quote
  #4  
Old April 28th, 2003, 11:25 AM
a.koepke's Avatar
a.koepke a.koepke is offline
Second highest poster :p
Dev Shed God 5th Plane (7000 - 7499 posts)
 
Join Date: Jul 2001
Posts: 7,323 a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 8 h 13 m 55 sec
Reputation Power: 27
Sorry, i meant display them encrypted and then copy and paste them into program to decrypt them, with private key on your machine.

Reply With Quote
  #5  
Old April 28th, 2003, 11:32 AM
rob46 rob46 is offline
A Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2002
Location: dk
Posts: 267 rob46 User rank is Corporal (100 - 500 Reputation Level)rob46 User rank is Corporal (100 - 500 Reputation Level)rob46 User rank is Corporal (100 - 500 Reputation Level)rob46 User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 1 Day 17 h 6 m 48 sec
Reputation Power: 10
Thanks for the reply -

Well i'll read up on the GnuPG process. It does seem like a good idea. Personally i don't like the idea of sending personal information by email but i don't really know the security risks - if it was encrypted.

Someone i know said that they stored the order information (and CC info) on a seperate db. They logged into an admin section, got the info + processed the order, deleted the info, logged out.
The GnuPG sytem sounds pretty similar except that the info is encrypted whilst being held on the db.

I suppose if you are confident in your db / login authentication routine, there is not too much to worry about. Its just IF someone did get into the db, they would have the unprocessed CC complete with address etc...Potential for being risky.

Reply With Quote
  #6  
Old April 28th, 2003, 01:00 PM
a.koepke's Avatar
a.koepke a.koepke is offline
Second highest poster :p
Dev Shed God 5th Plane (7000 - 7499 posts)
 
Join Date: Jul 2001
Posts: 7,323 a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level)a.koepke User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 8 h 13 m 55 sec
Reputation Power: 27
Yeah, just having a secure site is not much, you really need to have confidence that even if someone breaks in there is nothing they can do. With CC numbers you need to be sure.

Reply With Quote
  #7  
Old April 29th, 2003, 08:59 AM
trevHCS trevHCS is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2002
Posts: 80 trevHCS User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 7
With most of our hotel sites which have secure booking facilities we just encrypt the form data and send it out by e-mail for them to decrypt. At least that way the most likely place for credit card theft is at the hotel, but the risk is spread far wider than if we had everything in a database.

As for security at the hotels, well, erm, make sure your credit card doesn't have a very high limit. :-)

Trev - who's seen it all!

Reply With Quote
  #8  
Old April 29th, 2003, 10:21 AM
rob46 rob46 is offline
A Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2002
Location: dk
Posts: 267 rob46 User rank is Corporal (100 - 500 Reputation Level)rob46 User rank is Corporal (100 - 500 Reputation Level)rob46 User rank is Corporal (100 - 500 Reputation Level)rob46 User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 1 Day 17 h 6 m 48 sec
Reputation Power: 10
Can you expand on the encrypted email method.

So your final CC form is over SSl (of course) - then the submit button puts the info into a sendmail program. So i assume you need a private / public key system to encrpyt / decrypt the data going in and out of the email.

Cheers

Reply With Quote
Reply

Viewing: Dev Shed ForumsOtherBeginner Programming > Credit Card Question


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 5 hosted by Hostway
Stay green...Green IT