encryption - Should sensitive information such as credit card number be encrypted even when transmitting using https? -
this in context of application in cloud communicating internal application through vpn on https connection. (both applications of same organization)
so, when using above things, required add additional layer of security encrypting credit card information other application needs decrypt using predefined key?
if dealing credit card numbers need follow pcidss. 4.1 states when sending cardholder information on open or public networks must "appropriately" encrypted. states https (so ssl/tls must enabled).
i appreciate not limiting question credit card information.
i things https absolutely fine. have had encrypt second user's password before (to validate information on form first user entered, bit signature) not related talking using https , encryption with.
your question might worth posting on @ security.stackexchange
Comments
Post a Comment