encryption - Should sensitive information such as credit card number be encrypted even when transmitting using https? -


this in context of application in cloud communicating internal application through vpn on https connection. (both applications of same organization)

so, when using above things, required add additional layer of security encrypting credit card information other application needs decrypt using predefined key?

if dealing credit card numbers need follow pcidss. 4.1 states when sending cardholder information on open or public networks must "appropriately" encrypted. states https (so ssl/tls must enabled).

i appreciate not limiting question credit card information.

i things https absolutely fine. have had encrypt second user's password before (to validate information on form first user entered, bit signature) not related talking using https , encryption with.

your question might worth posting on @ security.stackexchange


Comments

Popular posts from this blog

html - Outlook 2010 Anchor (url/address/link) -

javascript - Why does running this loop 9 times take 100x longer than running it 8 times? -

Getting gateway time-out Rails app with Nginx + Puma running on Digital Ocean -