Jump to content

[SOLVED] CC Handling


kmark

Recommended Posts

I have a small client who wishses to recieve credit card info online.  He does not expect a lot of orders but would like the capability.  So rather than have him paying authorize.net or someone like that percentages on transactions and monthly fees, i thought of a system that I thought would work and wondered if you saw any holes init.

 

They user has filled their cart and everything they reach the payment info page that is secured by SSL. 

They enter their credit card info that is needed and hit submit. 

The payment process page which is also secured by SSL then takes the CC# and info and encrypts it, the encypted info is then emailed to the store owner. 

He before hand is given a orphaned link to a SSL secured decrypt page that he can login to and enter the encrypted information

Then the submission will be processed on an SSL secured page and he will recieve the unencrypted information on the page.

He then enters that info into his payment terminal in his store. 

He then deletes the email with the encrypted CC info.

 

Is there a major security risk in this process?

Link to comment
Share on other sites

K, I read your post and realize that nothing is ever 100% safe.  The holes I see in this are the security of the machine receiving the emails, and the link to the decrypt page.  But aside from that, i guess I'm referring to on the online side of things is this a horrible process, or is this just not ideal?

Link to comment
Share on other sites

ANY system is breakable, given enough motivation, and time.  If you're willing to take on the liability of all that sensitive data, and the possible lawsuits that could result from a compromise, then what you have is ok (not perfect, but what is?).  I just want you to realize that you could be in for a world of hurt if someone got a hold of that data.

Link to comment
Share on other sites

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.