Precisely Speaking
February 04, 2012, 07:06:56 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: So what's news with you?  Tell us about it in "Getting To Know You"!
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Unencrypted Credit Cards in Prelude  (Read 714 times)
precisonline
President/Chief Technologist
Administrator
Rock Star
*****
Posts: 1524



WWW
« on: March 03, 2010, 10:18:22 AM »

In recent days we've learned that many Prelude sites are storing credit card numbers without encryption.  Activant has sent out an email blast about the issue, offering a replacement for Protobase if only the customer upgrades to v21.

Looking into the Prelude encryption/decryption routines, it appears they are largely hamstrung by the fact that Unidata's encryption/decryption isn't functional on pre-7.1 releases.  We have found a way, however, to leverage SB+'s encryption instead, but ... is that enough?

I'd like to get a dialogue going because - it would seem - we are all in this together.  Do you have any thoughts to share on this credit card issue?  Personally, I'm a little freaked out because it seems that something needs to be done - and reasonably soon - to mitigate what could otherwise be some pretty awful exposure.  And I'm not convinced that a major upgrade with its commensurate pain and adjustments offers the best option.
Logged

-Kevin
Accidents "happen"; success, however, is planned and executed.
CKilgore
Professional
***
Posts: 19



« Reply #1 on: March 03, 2010, 10:50:44 AM »

Personally, I would prefer an option in which the credit cards numbers are never in Prelude to begin with.

We have also upgraded to Unidata 7.1 without any problems even though Prelude said they wouldn't support that move.

-Chris
Logged

Chris Kilgore
Brake Supply Co., Inc.
Prelude ADS Version 20.2
precisonline
President/Chief Technologist
Administrator
Rock Star
*****
Posts: 1524



WWW
« Reply #2 on: March 03, 2010, 12:14:21 PM »

I agree, as long as not having the credit card numbers in Prelude has no operational impact.  And it appears that this is what Activant is proposing with this new whiz-band credit card thing to replace Protobase.  But is the hassle of upgrading to v21 - especially for those that are still back on 18 and 19 - worthy of the credit card change?
Logged

-Kevin
Accidents "happen"; success, however, is planned and executed.
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC Valid XHTML 1.0! Valid CSS!