- Posts: 241
- Thank you received: 5
POODLE Information for Your Authorize.Net Account
- cberry1971
-
Topic Author
- Offline
Less
More
11 years 11 months ago #177226
by cberry1971
POODLE Information for Your Authorize.Net Account was created by cberry1971
Hello.. I just got a email with the above (subject).
The email explains (and I want to confirm hikashop is up to date with this):
As you may be aware, an Internet-wide security issue, commonly referred to as POODLE, has been identified in the last two weeks and affects anyone using older Web browsers that use SSL version 3 (SSLv3), specifically Internet Explorer (IE) 6. This issue creates a vulnerability that could allow hackers to gain access to any connection using this outdated Web browser.
Authorize.Net itself is not vulnerable to POODLE, but we are making changes to our systems to assure that we are providing our merchants and their customers with the highest degree of security possible.
To that end, on November 4, 2014, we will be disabling the use of SSLv3 within our systems. This means that if your website or shopping cart solution uses SSLv3 to send transactions to Authorize.Net, you will no longer be able to process transactions. You will also no longer be able to access any secure Authorize.Net pages from IE6.
We expect that a minimal number of our merchants will be affected. However, because we do not control how your particular site or solution sends transactions to us, this change could potentially impact your transaction processing. Please immediately contact your web developer or shopping cart solution to see if you will need to make any changes to your site or solution before November 4th
Many thanks.
The email explains (and I want to confirm hikashop is up to date with this):
As you may be aware, an Internet-wide security issue, commonly referred to as POODLE, has been identified in the last two weeks and affects anyone using older Web browsers that use SSL version 3 (SSLv3), specifically Internet Explorer (IE) 6. This issue creates a vulnerability that could allow hackers to gain access to any connection using this outdated Web browser.
Authorize.Net itself is not vulnerable to POODLE, but we are making changes to our systems to assure that we are providing our merchants and their customers with the highest degree of security possible.
To that end, on November 4, 2014, we will be disabling the use of SSLv3 within our systems. This means that if your website or shopping cart solution uses SSLv3 to send transactions to Authorize.Net, you will no longer be able to process transactions. You will also no longer be able to access any secure Authorize.Net pages from IE6.
We expect that a minimal number of our merchants will be affected. However, because we do not control how your particular site or solution sends transactions to us, this change could potentially impact your transaction processing. Please immediately contact your web developer or shopping cart solution to see if you will need to make any changes to your site or solution before November 4th
Many thanks.
Please Log in or Create an account to join the conversation.
11 years 11 months ago #177235
by toolie
Replied by toolie on topic POODLE Information for Your Authorize.Net Account
I also received this email. I guess the question for HikaShop is, do you use SSLv3 in any of your code?
My transactions process on the Authorize.net website, so I don't think I'm affected, but I'd like a response from HikaShop one way or the other.
Thanks,
Toolie
My transactions process on the Authorize.net website, so I don't think I'm affected, but I'd like a response from HikaShop one way or the other.
Thanks,
Toolie
Please Log in or Create an account to join the conversation.
11 years 11 months ago #177243
by Jerome
Jerome - Obsidev.com
HikaMarket & HikaSerial developer / HikaShop core dev team.
Replied by Jerome on topic POODLE Information for Your Authorize.Net Account
Hi,
HikaShop (or Joomla) can asked to the customer to go in secure zone (so to use an HTTPS url) but the SSLv3 or SSLv2 choice is not related to HikaShop or Joomla, it's related to your web server configuration.
Regards,
HikaShop (or Joomla) can asked to the customer to go in secure zone (so to use an HTTPS url) but the SSLv3 or SSLv2 choice is not related to HikaShop or Joomla, it's related to your web server configuration.
Regards,
Jerome - Obsidev.com
HikaMarket & HikaSerial developer / HikaShop core dev team.
Please Log in or Create an account to join the conversation.
Less
More
- Posts: 116
- Thank you received: 7
11 years 11 months ago #177346
by stratacorps
Replied by stratacorps on topic POODLE Information for Your Authorize.Net Account
It is the payment gateway methodology used to connect to the authorize.net and/or PayPal payment gateway services that is pertinent to this notice from authorize.net (and PayPal). Not just the web hosting facility that hosts your Joomla!/hikashop website.
We have already had to patch several open cart and Zen cart payment gateway files on other e-commerce systems. I have not had the chance to determine if Hikashop is affected as well. I guess we will know after Nov 4.
We have already had to patch several open cart and Zen cart payment gateway files on other e-commerce systems. I have not had the chance to determine if Hikashop is affected as well. I guess we will know after Nov 4.
Please Log in or Create an account to join the conversation.
Time to create page: 0.177 seconds