Path: csiph.com!v102.xanadu-bbs.net!xanadu-bbs.net!feeder.erje.net!eu.feeder.erje.net!news.swapon.de!eternal-september.org!feeder.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail From: Mark Carroll Newsgroups: comp.programming Subject: Re: storing credit card data Date: Fri, 05 Sep 2014 08:26:16 +0100 Organization: none Lines: 25 Message-ID: <87r3zqmstj.fsf@ixod.org> References: <9854dc17-9c12-403f-8115-409a7bcdc77e@googlegroups.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Injection-Info: mx05.eternal-september.org; posting-host="1b3e5cba9e4d07a53741e6f3d1717925"; logging-data="3375"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/MAWExzYM9t/KvtEyUETLc" User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/23.4 (gnu/linux) Cancel-Lock: sha1:3CBVGkyN/QYD2wx8DsgQb0QaSBc= sha1:P+4wejKBtr8QgeRh8Zediwu23Q4= Xref: csiph.com comp.programming:4748 Robert Wessel writes: > On Thu, 4 Sep 2014 22:05:06 -0700 (PDT), b wrote: > >>What is the best way to store credit card data locally in an app? >> >>You will almost certainly want to use some type of encryption, but in the most obvious way you will have the key stored in the program. This seems like a locked house where the key is right next to the door - not very secure. (snip) > Best answer is *don't*, unless you absolutely have to. And if you > have to, follow the PCI DSS standards and advice. (snip) Good suggestion. I worked on a project that achieved PCI compliance. In that particular instance, the encryption key is not stored in the program itself. Into the running program multiple users, authenticated by their own cryptographic keys, each enter their own "part" of the encryption key for the credit card data, and the software then combines them and holds it in RAM only while it is actually running; also, if it is suspected that some part of the key might have been revealed, it is easy to generate a new key whose parts are distributed to those users, and a re-encryption of the whole database then proceeds. (The users interact with the program via a web interface so OWASP recommendations, etc., were also important.) -- Mark