Follow us on Twitter X-Cart on Facebook Wiki
Shopping cart software Solutions for online shops and malls
 

Upcoming X-Cart v 4.4.6 (now renamed to 4.5.0) & PCI-DSS requirements

 
Closed Thread
   X-Cart forums > News and Announcements
 
Thread Tools
  #141  
Old 04-06-2012, 09:07 AM
  cflsystems's Avatar 
cflsystems cflsystems is offline
 

Veteran
  
Join Date: Apr 2007
Posts: 14,191
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

Quote:
Originally Posted by totaltec
Guys, this might be the solution, not just for PayPal but for other processors as well.

Not really with the way QT implements things like that. Quantum Gateway has iframe payment page and it is implemented in 4.4.x BUT - instead of showing on the checkout page it shows on a separate page after you click on "place order" button.... Why they coded it like this I cannot understand
__________________
Steve Stoyanov
CFLSystems.com
Web Development
  #142  
Old 04-06-2012, 09:07 AM
  BCSE's Avatar 
BCSE BCSE is offline
 

X-Guru
  
Join Date: Apr 2003
Location: Ohio - bcsengineering.com
Posts: 3,065
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

Quote:
Originally Posted by cflsystems
Does that means that PP Advanced plan will take XC out of scope and customers stay ON the site for payment?

Yes. That's what I was meaning with my post above about the new methods they are starting to market that have been out for about 6 months for a few people.

They told me it doesn't have to be an iframe. They have 3 methods:
-Embedded - could be iframe
-Lightbox
-popup new browser (not as popular).

I've been told but not confirmed yet that this will be available for 4.4.7 coming out in May. We plan to make an integration for 4.1.x at the minimum and if we get enough request for other old versions of X-cart (4.2.x, 4.3.x, 4.4.0-4.4.6) then we will do those as well. That is unless X-cart plans to backport it but usually they don't for things like this.

Carrie
__________________
Custom Development, Custom Coding and Pre-built modules for X-cart since 2002!

We support X-cart versions 3.x through 5.x!

Home of the famous Authorize.net DPM & CIM Modules, Reward Points Module, Point of Sale module, Speed Booster modules and more!


Over 200 X-cart Mods available & Thousands of Customizations Since 2002 - bcsengineering.com

Please E-Mail us for questions/support!
  #143  
Old 04-06-2012, 11:05 AM
 
dmr8448 dmr8448 is offline
 

Senior Member
  
Join Date: Jun 2003
Posts: 123
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

So does x-cart support the Paypal payments Pro Hosted option?

https://cms.paypal.com/cms_content/GB/en_GB/files/developer/HostedSolution.pdf
__________________
Version 4.3.2
  #144  
Old 04-09-2012, 03:04 AM
  ambal's Avatar 
ambal ambal is offline
 

X-Cart team
  
Join Date: Sep 2002
Posts: 4,121
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

Quote:
Originally Posted by dmr8448
So does x-cart support the Paypal payments Pro Hosted option?

https://cms.paypal.com/cms_content/GB/en_GB/files/developer/HostedSolution.pdf


It is going to support it in some time.
__________________
Sincerely yours,
Alex Mulin
VP of Business Development for X-Cart
X-Payments product manager
  #145  
Old 04-10-2012, 07:35 PM
 
DPP DPP is offline
 

Advanced Member
  
Join Date: May 2009
Posts: 33
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

longest week of my life.
__________________
Version 4.4.5 X-Cart Gold
  #146  
Old 04-11-2012, 12:26 AM
  ambal's Avatar 
ambal ambal is offline
 

X-Cart team
  
Join Date: Sep 2002
Posts: 4,121
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

Quote:
Originally Posted by DPP
longest week of my life.

Someone is having a longer week anyway
http://krebsonsecurity.com/2012/03/mastercard-visa-warn-of-processor-breach/

You'd better be safe now than be someone everyone points at.
__________________
Sincerely yours,
Alex Mulin
VP of Business Development for X-Cart
X-Payments product manager
  #147  
Old 04-11-2012, 07:56 AM
 
dmr8448 dmr8448 is offline
 

Senior Member
  
Join Date: Jun 2003
Posts: 123
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

Does anyone have recommendations on companies to help with our clients PCI compliance?
__________________
Version 4.3.2
  #148  
Old 04-11-2012, 10:44 AM
 
aasun aasun is offline
 

Member
  
Join Date: Jan 2006
Posts: 19
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

SUPER interesting thread. We're a small development company with about 10 x-cart stores/clients. And we manage 100% of the software, development and training for our clients. The only thing we don't do for them is manage their internal manufacturing, production, or fulfillment processes.

I'll admit, it is a bit scary. First, I have to be able to understand all this well enough so that I can:
1. inform my clients and answer their questions with authority
2. provide alternatives that ensure PCI-DSS compliance for their stores and limit their liability
3. be able to implement and manage all of this for them

Aside from custom designs, all these sites are pretty simple/basic in their checkout processes: 1 gateway, all SSL, no credit card data stored, etc.

SO, I'll ask this question (I haven't seen this asked in this thread), and it seems like an obvious question:

What would it take for x-Cart to become PA-DSS validated?

It seems like it would be THE simplest/best solution for a majority of the small x-Cart stores out there that would already be fully PCI-DSS compliant if only x-Cart was PA-DSS validated. Yes?

So, can QT ponder this question and seriously look at what it would take? Even if there were restructuring and changes needed in the code requiring some retooling of my clients' sites (or even a small increase in the license cost of the base x-cart that is PA-DSS validated), I can speak on their behalf and say, "I'd rather make backend updates to my site to meet compliancy requirements than to change my merchant provider or change my customers' checkout experience, or to have to pay large sums to 'tack on an after-thought' solution." (that 'after thought' solution being a third-party bounce-customers-off-of-my-site solution).
__________________
aasun
  #149  
Old 04-11-2012, 10:59 AM
 
aasun aasun is offline
 

Member
  
Join Date: Jan 2006
Posts: 19
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

I did some searching on the PCI Council site for other shopping cart and store front ends that ARE PA-DSS validated. Right away, I see MivaMerchant, PinnacleCart, and even ZenCart(!) is PA-DSS validated. Here's the link to the current list I'm looking at:

https://www.pcisecuritystandards.org/approved_companies_providers/validated_payment_applications.php?agree=true#

These names are frequently brought up by clients when evaluating shopping cart software, and we always steer them to x-cart.

I think QT really needs to get on the ball and provide a core system that is PA-DSS compliant, rather than requiring an expensive add-on, or complex solution to meet this need. I'll be hard pressed to be able to continue to sell x-cart over these other main stream shopping cart solutions, otherwise.
__________________
aasun
  #150  
Old 04-11-2012, 11:23 AM
 
balinor balinor is offline
 

Veteran
  
Join Date: Oct 2003
Location: Connecticut, USA
Posts: 30,253
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

We all pressed them to do that aasun, but they opted to go the X-Payments route instead. They have made it clear that they have no plans to make their core cart compliant, especially after spending so much money getting X-Payments validated.
__________________
Padraic Ryan
Ryan Design Studio
Professional E-Commerce Development
Closed Thread
   X-Cart forums > News and Announcements



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 04:50 AM.

   

 
X-Cart forums © 2001-2020