Store credit card info with Security

Ask a Question related to ASP.NET Security, Design and Development.

  1. #1

    Default Store credit card info with Security

    Hello,

    How is the best solution to store the credit cardīs info in ASP.NET for
    E-commerce site?
    What kind of cryptography methods, manipulted with xml, that I could use???
    I Look in many sites, but I couldīt find any help

    Thx!

    Samir


    Samir A. Mamude Guest

  2. Similar Questions and Discussions

    1. Sending Secure Data (Credit Card info) through PDF email attachments?
      Does anyone know if data input INTO a pdf form (with editable fields) can be sent via email (as an attachment) SECURELY? Is this info out there for...
    2. From validation? [ credit card ]
      I want to have a form in my director movie where the user enters their credit card details. Does anyone know how I can validate the number to see...
    3. Credit card security question
      Hi all, I need some advice although it's not scrictly PHP related. What is the prefered method to get credit cards off a web server in an online...
    4. [PHP] Credit card/Debit card validation
      I have a mod10 validation script written in another scripting language. I could try to convert it if you would like but I am sure that someone has...
    5. Credit card/Debit card validation
      Does anyone know of a PHP routine to validate Credit/Debit cards? I've seen some convoluted Javascript scripts but want a PHP version so validation...
  3. #2

    Default Re: Store credit card info with Security

    Samir,

    The most secure option would be not to store credit card numbers. Any other
    option will provide an invitation to hackers, law suites, embarrassment,
    etc., so you should really think twice and consider whether the benefits
    outweigh the risks. Anyway, if there is a valid business need to store
    credit card info, you should encrypt it (unfortunately, you cannot use
    hashing because you will need to get the original plain text values).
    Encryption is no big deal here: there are tons of examples on the Web. The
    main problem you will need to solve is protection of encryption key, and
    there is not silver bullet here. Whether you use a public-private key or
    symmetric key, you will need to do something to protect it and it ain't
    easy. Depending on the type of your environment, support model, application
    requirements, and a number of other factors, you must pick the most secure
    option, which suites your needs. I would suggest checking the "Protect It:
    Safeguard Database Connection Strings and Other Sensitive Settings in Your
    Code" article
    ([url]http://msdn.microsoft.com/msdnmag/issues/03/11/ProtectYourData/[/url]), which
    offers some suggestions, but don't expect it (or anyone else who is not
    closely familiar with your application) to give you detailed instructions. I
    assume that you also realize that all transactions should be done over SSL
    (HTTPS).

    Alek

    "Samir A. Mamude" <mamude@terra.com.br> wrote in message
    news:efcgO0Y1DHA.3416@tk2msftngp13.phx.gbl...
    > Hello,
    >
    > How is the best solution to store the credit cardīs info in ASP.NET for
    > E-commerce site?
    > What kind of cryptography methods, manipulted with xml, that I could
    use???
    > I Look in many sites, but I couldīt find any help
    >
    > Thx!
    >
    > Samir
    >
    >

    Alek Davis Guest

Posting Permissions

  • You may not post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139