Solved

need website security advice

Posted on 2013-01-20
3
123 Views
Last Modified: 2013-10-30
The website Im working on excepts credit cards. An account can have many users.
I want to ge the option to the buyer to save his credit card info, so it makes the next checkout quicker... When I say the credit card info is saved, no information is saved on my servers for security, but when the user chooses to save their card info I send an XML string to the payment processor asking for a token to be able to rebill the same card. having said that, I want to give the option of the credit card holder to share the ability to place an order using his credit card saved on file to the users on his account providing he sets the right permissions... Any advice on this feature would be greatly appreciated. im also guessing if I would go forward I would create another table to place the users that have permission to use the credit card on file...
0
Comment
Question by:prowebinteractiveinc
3 Comments
 
LVL 17

Expert Comment

by:Dushan911
ID: 38799806
It's never gonna good idea to save credit card details on your system. Give Credit card company to manage those and best not to touch or save those details locally. Also there could legal issue.
0
 
LVL 108

Expert Comment

by:Ray Paseur
ID: 38800906
RUN, don't walk, to your bank and set up a meeting with them, your business lawyer and your payment processor that is giving you the XML token.  On the agenda will be PCI Compliance or its equivalent in your countries.  You need expert legal and technical advice on this topic, since mishandling such information can get you sued or land you in jail.  

My guess is that once one of your clients gives you permission to charge his credit card for the bills of another client, you will have a fiduciary obligation to cross-notify, and when that permission is withdrawn or expires, you will need to again cross-notify.  It's complicated and it has a lot of implications that go far beyond the advice you can get here at EE.  Get professional advice that is directly in consonance with your exact business situation!

Best regards, ~Ray
0
 
LVL 33

Accepted Solution

by:
Slick812 earned 500 total points
ID: 38803161
hello, ,  This can be risky as others have said, , however there are some " payment processors " as you say, that do have options to have another payment order to use stored credit info. If you have found that your " payment processor " is a good one (as one with ratings or BANK certifies), you must follow their procedures exactly for setting payment info (credit card) to "SAVE", I would guess that the <XML> string has no actual name or credit card numbers, just an account (your web company acct) ID and a User reference ID with a true or false to set the storing payment info. I am trying to say that you should not send any XML with credit card number and owners name, as this is a BIG RISK.
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

Deprecated and Headed for the Dustbin By now, you have probably heard that some PHP features, while convenient, can also cause PHP security problems.  This article discusses one of those, called register_globals.  It is a thing you do not want.  …
I imagine that there are some, like me, who require a way of getting currency exchange rates for implementation in web project from time to time, so I thought I would share a solution that I have developed for this purpose. It turns out that Yaho…
The viewer will learn how to count occurrences of each item in an array.
This tutorial will teach you the core code needed to finalize the addition of a watermark to your image. The viewer will use a small PHP class to learn and create a watermark.

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now