Magento Forum

   
Confusion about payment methods
 
Skew
Member
 
Total Posts:  31
Joined:  2007-08-31
Phoenix
 

I’m a little confused how it’s working—the website seems to be in a “test mode” where orders are accepted without verification (default credit card—which I don’t even see a way to verify—and paypal).

What am I obviously missing?

 
Magento Community Magento Community
Magento Community
Magento Community
 
Skew
Member
 
Total Posts:  31
Joined:  2007-08-31
Phoenix
 
Ron Seigel - 01 September 2007 05:44 PM

The default CC module saves the CC info in the database presumably so you can process it manually.

I don’t think PayPal is finished and functional yet.

Ok, that makes a little more sense. The default CC module seems to only be useful for phone orders (when the admins would need to add it manually), in which case you wouldn’t want it available to everyone… otherwise you’d want it automatically verified, no?

 
Magento Community Magento Community
Magento Community
Magento Community
 
RoyRubin
Magento Team
 
Avatar
Total Posts:  968
Joined:  2007-08-07
Los Angeles, CA
 

Skew - Not necessarily. You can collect the CC information and then run it manually offline or through a virtual gateway.

 
Magento Community Magento Community
Magento Community
Magento Community
 
Skew
Member
 
Total Posts:  31
Joined:  2007-08-31
Phoenix
 

Got it. Thank you.

This brings me to another question: f there is a customer that needs a custom order that you wouldn’t necessarily want available to everyone, will be there any options available for handling this smoothly, or would it have to be charged through a terminal (in which case it’s not on the site and becomes kind of a pain splitting orders up here and there)?

 
Magento Community Magento Community
Magento Community
Magento Community
 
YoavKutner
Guru
 
Avatar
Total Posts:  491
Joined:  2007-08-08
 

This should be possible when we roll out our admin order management module (or as referred to sometimes as call center module)

 
Magento Community Magento Community
Magento Community
Magento Community
 
Skew
Member
 
Total Posts:  31
Joined:  2007-08-31
Phoenix
 
yoav - 02 September 2007 11:13 PM

This should be possible when we roll out our admin order management module (or as referred to sometimes as call center module)

Great. Is this going to be in the first official release, or in a beta?

 
Magento Community Magento Community
Magento Community
Magento Community
 
austinstorm
Member
 
Avatar
Total Posts:  31
Joined:  2007-08-31
Moscow, ID
 

Skew… I don’t see it in the roadmap, but considering that it’s already in the admin menus I would assume that it’s in the works soon, probably by beta 2.

Ron, I worked for an internet company for a year that just stored CCs and processed them through auth.net manually. They never had security problems, and purged the CC database on the site about once a month. During my tenure I was able to change them to a better system (they had to manually type in hundreds of numbers a week), but I don’t think it was a huge security problem.

My experience and reading has led me to believe that a lot of the “don’t store cc numbers” is just rhetoric designed to fight public perception that shopping on the internet is unsafe, when in reality most credit card fraud happens at restaurants and brick-and-mortar retail stores.

But yes, auth.net integration is a must.

 
Magento Community Magento Community
Magento Community
Magento Community
 
johannes80
Jr. Member
 
Total Posts:  9
Joined:  2007-08-31
 

A quick note for Swedish merchants. I don’t think it’s legal to store people’s credit card numbers over here. At least it wasn’t two-three years ago. Please check this before using those modules or you might come in trouble.

It is really stupid to save the numbers unencrypted in a database, if that’s what this module does. What if people set up Magento in a shared hosting environment and it get hacked because of a bug in a software someone else has installed? Just a thought..

 
Magento Community Magento Community
Magento Community
Magento Community
 
Rusty
Jr. Member
 
Total Posts:  3
Joined:  2007-08-31
 

Will CC #’s be encrypted?
I believe to be PCI compliant they would have to be.
Will there be a encryption key that is stored locally to be able access CC #’s?

Thank you,
Rusty

 
Magento Community Magento Community
Magento Community
Magento Community
 
mckooter
Sr. Member
 
Avatar
Total Posts:  91
Joined:  2007-08-31
 

when you install it gives you an encryption key and states its used for passwords and CC #’s if im not mistaken

 
Magento Community Magento Community
Magento Community
Magento Community
 
RoyRubin
Magento Team
 
Avatar
Total Posts:  968
Joined:  2007-08-07
Los Angeles, CA
 

Credit cards are encrypted in the database - yes.

 
Magento Community Magento Community
Magento Community
Magento Community
Magento Community
Magento Community
    Back to top