Storing credit card numbers??

1 view
Skip to first unread message

shanewho

unread,
Jun 4, 2010, 11:02:05 AM6/4/10
to substruct
I've noticed that Substruct stores credit card numbers in the database
temporarily, and sometimes longer even if you have checked the option
to only keep the last 4 digits. If the transaction fails for some
reason, the # is not cleared out and can be seen in the orders account
info page. Also, if the user enters their credit card #, goes to the
confirm page (just before the order is submitted), but leaves the site
before the final submission, their # stays in the database.

I could be wrong, but I think U.S. law requires you to meet some
security regulations if you are storing customers credit card #'s in
your system, which I doubt most hosting providers do not meet.

Am I off base here, or does this concern anyone else?

Roger Pack

unread,
Jun 4, 2010, 8:05:49 PM6/4/10
to subs...@googlegroups.com
patches are welcome, though I'm not sure if the second problem you
mention can be avoided automatically.
-r

> --
> You received this message because you are subscribed to the Google Groups "substruct" group.
> To post to this group, send email to subs...@googlegroups.com.
> To unsubscribe from this group, send email to substruct+...@googlegroups.com.
> For more options, visit this group at http://groups.google.com/group/substruct?hl=en.
>
>

seth b

unread,
Jun 7, 2010, 1:30:39 PM6/7/10
to subs...@googlegroups.com
It's not a "US law", but it is a suggestion to not store credit cards
in the DB for PCI DSS certification / regulations.

The preference in Substruct is supposed to give site owners a choice
if they'd like to store cards or not. Some merchants like to be able
to contact the cardholder and potentially run failed transactions
after speaking with them.

I'd be open to looking at well tested patches that only store the card
in memory until the order is completed. If it concerns you that much,
please feel free to submit one.

- Seth

--------------------
http://subimage.com
http://twitter.com/subimage

Reply all
Reply to author
Forward
0 new messages