Authorize.net AIM recurring security

Discussion in 'Payments processing' started by marketflavor, Feb 3, 2007.

  1. marketflavor

    marketflavor New Member

    Joined:
    Feb 2, 2007
    Messages:
    3
    Hi,

    I am looking to purchase amember on behalf of a client (I'm building the website) and client has already gotten authorize.net account. He wants to do recurring billing. I understand we must use AIM and that when using AIM, Authorize.net stores the CC info on the server. We are on a shared hosting environment, and I have concerns about storing credit card data on the server. I've done some searching on the forums, and it seems like many people use this method. Yet, I see no concern about amember holding the credit card information on the server. Is there nothing to worry about? What's the deal?
  2. alex

    alex aMember Pro Customer Staff Member

    Joined:
    Jan 24, 2004
    Messages:
    6,021
    We DO NOT RECOMMEND to use credit card plugins that store credit card info on shared hostings at all. It is for any software, not only for aMember Pro.
  3. marketflavor

    marketflavor New Member

    Joined:
    Feb 2, 2007
    Messages:
    3
    Thanks. We'll probably go with PayPal.
  4. accularian

    accularian Online Macintosh support — aMember Guru.

    Joined:
    Dec 12, 2006
    Messages:
    41
  5. alex

    alex aMember Pro Customer Staff Member

    Joined:
    Jan 24, 2004
    Messages:
    6,021
    Yes, if you enable recurring billing.
  6. alex

    alex aMember Pro Customer Staff Member

    Joined:
    Jan 24, 2004
    Messages:
    6,021
  7. accularian

    accularian Online Macintosh support — aMember Guru.

    Joined:
    Dec 12, 2006
    Messages:
    41
    Alex,

    It appears that the stored credit card info is not very readable in the SQL database, you have done a good job of securing it. Can you elaborate on the risks? It looks pretty secure to me.

    Dana Haynes
    Accularian
    http://www.accularian.com
  8. alex

    alex aMember Pro Customer Staff Member

    Joined:
    Jan 24, 2004
    Messages:
    6,021
    It is secure enough if non-programmer will be attacking you. I will not describe how, but expirienced programmer can decode this information if he has full access to your website and database. So I STRONGLY do not recommend to run credit card storage on shared hostings.
  9. dan_kelly

    dan_kelly New Member

    Joined:
    Aug 29, 2006
    Messages:
    91
    I agree...

    DO NOT store credit card information on a SHARED server, get a "Dedicated" server instead. (Also, not "Virtual Dedicated"; that's just glorified shared.)

    1&1 has good servers starting at $99/mo.

    To OUR Success,
    Dan Kelly
    AskDanKelly.com
    MiniSiteSecretsRevealed.com

Share This Page