X-Cart: shopping cart software

X-Cart forums (https://forum.x-cart.com/index.php)
-   News and Announcements (https://forum.x-cart.com/forumdisplay.php?f=28)
-   -   Upcoming X-Cart v 4.4.6 (now renamed to 4.5.0) & PCI-DSS requirements (https://forum.x-cart.com/showthread.php?t=63061)

keystone 03-26-2012 10:15 AM

Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
 
Would the new version of BCSE DPM solution be PA-DSS certified? If not and we use it we can still be fined right? Sometimes I wish I could go back to when we hunted our own food and lived in huts. Why does x-carts home page say 100% pci-dss compliant if we have to go through all this?

balinor 03-26-2012 10:16 AM

Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
 
The DPM module doesn't need to be certified - that's why it is such an elegant solution. You are technically entering the CC data directly into Auth.net, thus taking the cart out of the equation.

elmirage001 03-26-2012 10:43 AM

Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
 
Quote:

Originally Posted by seyfin
Hello X-Carters,

We would like to inform you about major changes in upcoming X-Cart v 4.4.6 (to be released very soon, in a week or so):

3) USPS shipping calculator module will be completely revised and updated to meet the latest USPS APIs requirements.

Dear Seyfin, could you please fill us in a little more about the USPS API changes. I found the following information below which to me implies that starting April 1st we will no longer be able to give real time rate quotes (domestic) without being on RateV4, and I'm confused about IntlRateV2. Will your upgrade be only for 4.4.6? Will there be a fix for previous x-cart versions? Is there a RateV3 and if so are we all fine? Please advise. Thank you!
Quote:

- All Rate Calculator API integrators are encouraged to migrate to the latest API versions (RateV4, IntlRateV2):

- Rate and RateV2 versions of the domestic Rate Calculator will be retired on March 31, 2012, requiring all integrators to migrate to the latest versions;

ynotcreative 03-26-2012 11:04 AM

Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
 
Quote:

Originally Posted by balinor
Because that would be against PA-DSS compliance regs - people would use it WITHOUT the DPM plug-in and be out of compliance. They would need to come up with a way to only enable it if the DPM plug-in is present.


Then x-cart should offer a plug-in themselves for DPM. Just removing an option in return for a $1200 scare-tactic-laden option is wrong. When most people purchased x-cart, they did so with the advertised feature of having payment gateway options from Authorize.net. Furthermore, the customization options that x-cart offers made it seem like we could keep the nice clean behind-the-scenes payment. To remove that and force the polar opposite or a high-priced solution goes against what purchasing x-cart used to be all about. LightweightCommerce is going to be even more confining. Most people bought x-cart to be used as a storefront first and foremost. Removing critical major features in return for a you must buy x-payment or else mentality is getting old.

Despite past misgivings, I just had clientele purchase five new licenses of Pro. Now I am starting to wonder if that was the wrong thing to do. I wanted to keep a little faith, but this throws that faith all alway, almost as much as the switch to LiteCommerce as a core and product name.

I renew my request. I want a justification of the X-Payments price tag if they want any licenses from us or our clientele.

balinor 03-26-2012 11:14 AM

Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
 
Unfortunately they don't have a choice ynotcreative, you can no longer use a non-compliant cart to process credit cards. If you don't want to comply, that is your right, but the $50,000 fine isn't a scare tactic, it is a reality of the new credit card processing age.

Just install 4.4.5 and you won't have to worry about this.

ynotcreative 03-26-2012 11:19 AM

Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
 
Quote:

Originally Posted by balinor
Unfortunately they don't have a choice ynotcreative, you can no longer use a non-compliant cart to process credit cards. If you don't want to comply, that is your right, but the $50,000 fine isn't a scare tactic, it is a reality of the new credit card processing age.

Just install 4.4.5 and you won't have to worry about this.



Because this is about principle. Yes, X-Cart could release a DPM solution, which someone said takes care of the issue elegantly. If BCSE or CFL could write a plug-in, why can't X-Cart?

keystone 03-26-2012 11:43 AM

Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
 
Quote:

Just install 4.4.5 and you won't have to worry about this.


How will using 4.4.5. fix the issue? The option for Authorize.net AIM is still there. I just updated to that version in my dev directory.

balinor 03-26-2012 12:03 PM

Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
 
Because 4.4.5 still has the credit card processors - 4.4.6 will not.

keystone 03-26-2012 12:05 PM

Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
 
If you don't mind me asking, what are doing with your sites balinor?

balinor 03-26-2012 12:17 PM

Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements
 
I don't run any sites personally, but we've taken just about every approach with our clients - from DPM to External Gateways like PayPal and Auth.net SIM. Need to weigh the cost/benefit - you want the best solution for your customers that doesn't break the bank for you.


All times are GMT -8. The time now is 05:10 AM.

Powered by vBulletin Version 3.5.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.