Stone Edge Technologies User Forum
Stone Edge Technologies User Forum
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 The Order Manager
 Ask Other Users
 No Credit Card Hide in Manual Orders
 New Topic  Reply to Topic
 Printer Friendly
Author Previous Topic Topic Next Topic  

dpickette
New Member

USA
10 Posts

Posted - 10/16/2009 :  11:59:57 AM  Show Profile  Reply with Quote
On the newest version 5.904 the full credit card information is displayed when you bring up an existing customer in Manual Orders. The system parameters the CC hide only works for View Orders and NOT Manual Orders. Does anyone else have a problem with this serious lack of security!

David Pickette
Uni Key Health Systems

JaredSE
Senior Member

730 Posts

Posted - 10/16/2009 :  5:15:08 PM  Show Profile  Reply with Quote
That is intentional and necessary for that form at this point. Also when you think about it, your sales people are typing the full credit card number in there anyway when they're on the phone with your customers. Nothing is preventing them or anyone who walks by them from acquiring those card numbers.
Go to Top of Page

geckoday
Member

339 Posts

Posted - 10/17/2009 :  10:36:04 AM  Show Profile  Visit geckoday's Homepage  Reply with Quote
The card number should never be shown unless absolutely necessary. Displaying it in this case is a violation of PCI-DSS requirement 3.3 which states:
quote:

Mask PAN when displayed (the first six and last four digits are the maximum number of digits to be displayed).
Notes:
This requirement does not apply to employees and other parties with a legitimate business need to see the full PAN.


When bringing up an existing customer the employee has no business reason to see the full PAN. The card type and last 4 is sufficient to confirm with the customer that the correct card will be charged. Stone Edge should consider this a serious security flaw and issue an immediate fix.

Ralph Day
Snow River
http://www.snowriver.com

Order Manager Version 5.916
Access 2003 SP3 w/hotfix

Edited by - geckoday on 10/17/2009 10:37:10 AM
Go to Top of Page

dpickette
New Member

USA
10 Posts

Posted - 10/19/2009 :  2:23:36 PM  Show Profile  Reply with Quote
I agree with Mr Day, this issue needs to be addressed immediately. As it stands now we are in violation with our Data Security Standards because of this change in the current version.

David Pickette
Uni Key Health Systems
Go to Top of Page

Barney Stone
Administrator

USA
6273 Posts

Posted - 10/19/2009 :  4:30:01 PM  Show Profile  Visit Barney Stone's Homepage  Reply with Quote
I fixed this for the next release. Look for it in a week or two.

Barney Stone, President
Stone Edge Technologies, Inc.
610-994-3699 ext. 111
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Reply to Topic
 Printer Friendly
Jump To:
Stone Edge Technologies User Forum © Stone Edge Technologies, Inc. Go To Top Of Page
Powered By: Snitz Forums 2000 Version 3.4.06