Re: online stores and security.

by "Phil Babcock" <pbabcock(at)bgsgroup.com>

 Date:  Wed, 18 Oct 2000 10:16:30 -0400
 To:  "Mike Taylor" <lonewolf(at)one.net>,
hwg-techniques(at)hwg.org
 References:  one
  todo: View Thread, Original
Malignant retrieval of the information that comes back from a "secure"=
 server isn't easy, but it can be done.  On our confirmation pages we=
 display nothing but the order number and a thank you.  We then have an=
 order-history page where the person could look up what was on the order if=
 they want to.  We definately never return the credit card info to them=
 anywhere, email included.  If they want to confirm the credit card info=
 they have on file they have to call.

hth
phil.


*********** REPLY SEPARATOR  ***********

On 10/18/2000 at 9:08 AM Mike Taylor wrote:

>I had a customer who was concerned that after he entered his information,
>we displayed it back to him on the screen on an order confirmation
>page.  He was upset that his credit card number was shot back to him and
>that even though our store had a valid SSL certificate, he feels his
>credit card information has been compromised.
>
>I think he's overreacting.  How do those of you out there handle your
>order confirmation pages?  What we always did (up until yesterday) was
>display the information as a confirmation for the customer's benefit and
>record keeping.  We also send them an email confirmation (we do the online
>confirmation for immediacy).  I can't imagine a circumstance where someone
>could retrieve someone's credit card information being displayed back to
>the client on a secure server.
>
>Thoughts?
>
>Mike

HWG hwg-techniques mailing list archives, maintained by Webmasters @ IWA

This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.