Re: online stores and security.
by "Phil Babcock" <pbabcock(at)bgsgroup.com>
|
| Date: |
Wed, 18 Oct 2000 10:16:30 -0400 |
| To: |
"Mike Taylor" <lonewolf(at)one.net>, hwg-techniques(at)hwg.org |
| References: |
one |
| |
todo: View
Thread,
Original
|
|
Malignant retrieval of the information that comes back from a "secure"=
server isn't easy, but it can be done. On our confirmation pages we=
display nothing but the order number and a thank you. We then have an=
order-history page where the person could look up what was on the order if=
they want to. We definately never return the credit card info to them=
anywhere, email included. If they want to confirm the credit card info=
they have on file they have to call.
hth
phil.
*********** REPLY SEPARATOR ***********
On 10/18/2000 at 9:08 AM Mike Taylor wrote:
>I had a customer who was concerned that after he entered his information,
>we displayed it back to him on the screen on an order confirmation
>page. He was upset that his credit card number was shot back to him and
>that even though our store had a valid SSL certificate, he feels his
>credit card information has been compromised.
>
>I think he's overreacting. How do those of you out there handle your
>order confirmation pages? What we always did (up until yesterday) was
>display the information as a confirmation for the customer's benefit and
>record keeping. We also send them an email confirmation (we do the online
>confirmation for immediacy). I can't imagine a circumstance where someone
>could retrieve someone's credit card information being displayed back to
>the client on a secure server.
>
>Thoughts?
>
>Mike
HWG hwg-techniques mailing list archives,
maintained by Webmasters @ IWA
This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.