<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Storing Private Information In An Online Database</title>
	<atom:link href="http://aldebaranwebdesign.com/blog/storing-private-information-in-an-online-database/feed/" rel="self" type="application/rss+xml" />
	<link>http://aldebaranwebdesign.com/blog/storing-private-information-in-an-online-database/</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Sat, 15 May 2010 18:18:37 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Jill Olkoski</title>
		<link>http://aldebaranwebdesign.com/blog/storing-private-information-in-an-online-database/comment-page-1/#comment-5148</link>
		<dc:creator>Jill Olkoski</dc:creator>
		<pubDate>Fri, 31 Jul 2009 16:35:23 +0000</pubDate>
		<guid isPermaLink="false">http://aldebaranwebdesign.com/blog/?p=634#comment-5148</guid>
		<description>Hi Tina,
Excellent question. So far, I&#039;ve never had an ecommerce client who needed to do a credit check. I presume that this kind of check would be necessary to get a loan, versus making a purchase. In general, I would NEVER submit my SSN number via any online service, unless it was the government or one of the big three credit rating agencies. Just too dangerous, my personal opinion. Whenever I&#039;ve been required to give SSN number, it was either via phone, or via fax.

Note, that I&#039;ve been contacted by a few loan companies who wanted me to do just this, to collect SSN numbers and send them in the clear, via email. I&#039;ve refused these jobs, concerned they might be scams. 

Now, I&#039;m no security expert. I have heard that it&#039;s possible to encrypted in the database, but I haven&#039;t done this before - it&#039;s simply out of the scope of what I&#039;m comfortable doing. If you need to collect and store SSN numbers, you should consult with a web developer security expert who has done this type of thing before. I&#039;m sure there are other things as well, it&#039;s just out of my field of expertise.</description>
		<content:encoded><![CDATA[<p>Hi Tina,<br />
Excellent question. So far, I&#8217;ve never had an ecommerce client who needed to do a credit check. I presume that this kind of check would be necessary to get a loan, versus making a purchase. In general, I would NEVER submit my SSN number via any online service, unless it was the government or one of the big three credit rating agencies. Just too dangerous, my personal opinion. Whenever I&#8217;ve been required to give SSN number, it was either via phone, or via fax.</p>
<p>Note, that I&#8217;ve been contacted by a few loan companies who wanted me to do just this, to collect SSN numbers and send them in the clear, via email. I&#8217;ve refused these jobs, concerned they might be scams. </p>
<p>Now, I&#8217;m no security expert. I have heard that it&#8217;s possible to encrypted in the database, but I haven&#8217;t done this before &#8211; it&#8217;s simply out of the scope of what I&#8217;m comfortable doing. If you need to collect and store SSN numbers, you should consult with a web developer security expert who has done this type of thing before. I&#8217;m sure there are other things as well, it&#8217;s just out of my field of expertise.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tina</title>
		<link>http://aldebaranwebdesign.com/blog/storing-private-information-in-an-online-database/comment-page-1/#comment-5147</link>
		<dc:creator>Tina</dc:creator>
		<pubDate>Fri, 31 Jul 2009 14:48:51 +0000</pubDate>
		<guid isPermaLink="false">http://aldebaranwebdesign.com/blog/?p=634#comment-5147</guid>
		<description>This is good information.  I&#039;m curious how you would handle a client who requires Social Security number information necessary to process a credit check on a customer.

Suppose the client is very adamant that this information be captured, as it&#039;s vital to his business.  

I would assume the obvious:  if it&#039;s to be stored in a database, the SS number needs to be encrypted and the data transfer needs to be via SSL.  But what other security measures can be taken that haven&#039;t already been mentioned above?</description>
		<content:encoded><![CDATA[<p>This is good information.  I&#8217;m curious how you would handle a client who requires Social Security number information necessary to process a credit check on a customer.</p>
<p>Suppose the client is very adamant that this information be captured, as it&#8217;s vital to his business.  </p>
<p>I would assume the obvious:  if it&#8217;s to be stored in a database, the SS number needs to be encrypted and the data transfer needs to be via SSL.  But what other security measures can be taken that haven&#8217;t already been mentioned above?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
