X-Cart: shopping cart software

X-Cart forums (https://forum.x-cart.com/index.php)
-   News and Announcements (https://forum.x-cart.com/forumdisplay.php?f=28)
-   -   X-Payments 1.0 beta5 announcement (https://forum.x-cart.com/showthread.php?t=53981)

Emerson 07-02-2010 08:28 AM

Re: X-Payments 1.0 beta5 announcement
 
Quote:

Originally Posted by cflsystems
Thanks Ralph, that explains a lot. I wonder did QT ever hired you at least as an advisor. Probably mosty of this mess would have been avoided if they did


I always wondered the same thing :/

canuck 07-02-2010 09:22 AM

Re: X-Payments 1.0 beta5 announcement
 
Quote:

Originally Posted by geckoday
If you are a merchant that must fill out SAQ D (most of us aren't unless you store credit card numbers) then 2.2.1 means you must run your web server software and database server software on separate servers and that the database server can't be accessed from the internet. If you meet the requirements to fill out SAQ C (mostly meaning you don't store credit card numbers) 2.2.1 doesn't even apply to you.


Interesting you say that - I agree with you. How about if the merchant is taking card #'s occasionally by phone and processing those payments through a web terminal, but not storing card data beyond that. Trying to get a direct answer so far has been challenging.

geckoday 07-02-2010 10:07 AM

Re: X-Payments 1.0 beta5 announcement
 
Quote:

Originally Posted by canuck
Interesting you say that - I agree with you. How about if the merchant is taking card #'s occasionally by phone and processing those payments through a web terminal, but not storing card data beyond that. Trying to get a direct answer so far has been challenging.

If you are entering card numbers on your PC through a browser to a payment gateway it won't push you to SAQ D, you're still eligible for SAQ C. But your PCI validation scope now goes beyond your web server and includes the PC's, switches, firewalls, etc. at the location where you enter the card data from the phone orders. This is assuming you are using a hosting service for your web site and not hosting it yourself on the same network the PC you use to enter the card numbers is on.

If you're trying to get to SAQ A by using a gateway hosted payment page or an iframe or redirect gateway api where the customer credit card data posts to directly to the gateway server unfortunately those phone orders push you into SAQ C.

geckoday 07-02-2010 10:49 AM

Re: X-Payments 1.0 beta5 announcement
 
Quote:

Originally Posted by ambal
If you know something about deadlines set by various payment gateways don't hesitate to post that information and proof links here or PM me.

Not what I'd call an authoritative source as its not hosted on the VISA Europe site (though the site seems reputable) but it looks like December 2012 is the VISA Europe deadline.

http://www.hftp.org/Content/Forms/EHTEC/EHTECPresentations/2010/PCIDSS.pdf

canuck 07-02-2010 11:31 AM

Re: X-Payments 1.0 beta5 announcement
 
Ralph, you're good. I think I should retain you as a consultant.
Did you work with a QSA for this bachelors in PCI you seem to have? :wink:

I've called 3 that have Canadian offices so far and still waiting for call backs.

finestshops 07-02-2010 03:03 PM

Re: X-Payments 1.0 beta5 announcement
 
By the way, in X-cart defense - this is not X-cart specific issue. There are only 3 unknown shopping carts are on that certified list right now and even huge players like Magento are at the same stage of testing a bridge module as X-cart. And Magento Enterprise is $12,000/year software. Still, would be nice to have that X-payments ready earlier and working on PHP 5.2.

EN4U 07-02-2010 03:26 PM

Re: X-Payments 1.0 beta5 announcement
 
Quote:

Originally Posted by 27stars
By the way, in X-cart defense - this is not X-cart specific issue. There are only 3 unknown shopping carts are on that certified list right now


Not true. With their new production release 7, aka “Wombat,” Miva Merchant is now a fully PCI & PA-DSS certified shopping cart application.

Ive been complaint over there with my Lingerie site for 2 plus weeks now. Miva cared enough to make the adjustments to there cart so all remained the same, thus we didn't have to do cloak and dagger voodoo stuff. To bad i cant say the same for the Xcart team.
Anyways, we decided for our two sites on this platform to sit back and wait to see what transpires in the next week or two. We have received no notices etc, from anyone as of yet. I think as the days go on things may become more clear as reports come in and the fog clears. At least that's what i hope will happen.

finestshops 07-02-2010 03:41 PM

Re: X-Payments 1.0 beta5 announcement
 
My bad, I was checking here and got only 3 results:

https://www.pcisecuritystandards.org/security_standards/vpa/

Application Type: Shopping Cart and Storefront

there are 14 vendors now. Still do not see Miva but they probably have a different official company name.

cflsystems 07-02-2010 05:17 PM

Re: X-Payments 1.0 beta5 announcement
 
Well I would be willing to take part of the blame for not being ready. QT is at fault here because they started too late to look and work on a solution. I don't know why - maybe they were not adviced properly in the beginning, maybe they were thinking they can certify xcart itself, or maybe is a lack of management and understanding of how serious this is. But let's face it - most of us didn't do anything. We were just waithing on QT to provide solution. There were very few people here in the forum trying to push QT. And I think most of us were thinking - dead line is too far yet, we have time. Well when it turns out we don't have time and we don't have a solution we all got mad and frustrated with QT. Not trying to take out the blame off of QT but maybe we are also to blame a little. 7/1/2010 is behind us already. Whatever's done is done. Let's hope that is not gonna take more time

dmr8448 07-02-2010 05:47 PM

Re: X-Payments 1.0 beta5 announcement
 
Does any one have an example of how the x-payments works during the checkout process of x-cart. So if someone selects "credit card" as there payment option...what happens.

Is the user then taken to the x-payments system and are they totally out of x-cart then.

Will this still look seamless to the end user that is shopping on the site?


All times are GMT -8. The time now is 06:10 PM.

Powered by vBulletin Version 3.5.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.