[ic] Credit Card Info

Jim Balcom interchange-users@interchange.redhat.com
Sat Nov 3 17:57:05 2001


On Sat, 3 Nov 2001, Yahoo wrote:

Y>>This may be very novice question, but we are not a high volume operation, we
Y>>really do not need a processing entity at the moment, so I was asked to have
Y>>daily reports with clients orders including card #s, I have come to discover
Y>>that the card # is a variable not a field ( I think ), anybody ever done
Y>>this before could enlighten us,

I suggest that you educate the people that are asking you to do this to the
high risks of allowing credit card numbers to become visible to people that
don't have a need for access to them in order to process the order.

Perhaps you are a small shop like mine, in which case it's no problem.
Scotty and I process orders interchangeably, and so we both have full access
to all of the computers, card #,s etc.

But, once you get much bigger than that, you end up having these number
floating around, either on computers, or on paper, where people can access
them have no need to, or worse yet, where someone can hack into the computer
and capture them.

-= Jim =-

----------------------------------------------------------------
Jim's Linux-Operated Underground Bomb Shelter

Tagline for Saturday, November 03, 2001 at 17:50 PM:
I tried being reasonable once. I didn't like it.

----------------------------------------------------------------
This Linux System has been up 200 hours

My web page: http://www.idk-enterprises.com
----------------------------------------------------------------