POODLE Information for Your Authorize.Net Account

  • Posts: 241
  • Thank you received: 5
10 years 9 months ago #177226

Hello.. I just got a email with the above (subject).

The email explains (and I want to confirm hikashop is up to date with this):

As you may be aware, an Internet-wide security issue, commonly referred to as POODLE, has been identified in the last two weeks and affects anyone using older Web browsers that use SSL version 3 (SSLv3), specifically Internet Explorer (IE) 6. This issue creates a vulnerability that could allow hackers to gain access to any connection using this outdated Web browser.

Authorize.Net itself is not vulnerable to POODLE, but we are making changes to our systems to assure that we are providing our merchants and their customers with the highest degree of security possible.

To that end, on November 4, 2014, we will be disabling the use of SSLv3 within our systems. This means that if your website or shopping cart solution uses SSLv3 to send transactions to Authorize.Net, you will no longer be able to process transactions. You will also no longer be able to access any secure Authorize.Net pages from IE6.

We expect that a minimal number of our merchants will be affected. However, because we do not control how your particular site or solution sends transactions to us, this change could potentially impact your transaction processing. Please immediately contact your web developer or shopping cart solution to see if you will need to make any changes to your site or solution before November 4th


Many thanks.

Please Log in or Create an account to join the conversation.

  • Posts: 54
  • Thank you received: 1
  • Hikashop Business
10 years 9 months ago #177235

I also received this email. I guess the question for HikaShop is, do you use SSLv3 in any of your code?

My transactions process on the Authorize.net website, so I don't think I'm affected, but I'd like a response from HikaShop one way or the other.

Thanks,

Toolie

Please Log in or Create an account to join the conversation.

  • Posts: 26264
  • Thank you received: 4043
  • MODERATOR
10 years 9 months ago #177243

Hi,

HikaShop (or Joomla) can asked to the customer to go in secure zone (so to use an HTTPS url) but the SSLv3 or SSLv2 choice is not related to HikaShop or Joomla, it's related to your web server configuration.

Regards,


Jerome - Obsidev.com
HikaMarket & HikaSerial developer / HikaShop core dev team.

Also helping the HikaShop support team when having some time or couldn't sleep.
By the way, do not send me private message, use the "contact us" form instead.

Please Log in or Create an account to join the conversation.

  • Posts: 116
  • Thank you received: 7
  • Hikashop Business
10 years 9 months ago #177346

It is the payment gateway methodology used to connect to the authorize.net and/or PayPal payment gateway services that is pertinent to this notice from authorize.net (and PayPal). Not just the web hosting facility that hosts your Joomla!/hikashop website.

We have already had to patch several open cart and Zen cart payment gateway files on other e-commerce systems. I have not had the chance to determine if Hikashop is affected as well. I guess we will know after Nov 4.

Please Log in or Create an account to join the conversation.

Time to create page: 0.051 seconds
Powered by Kunena Forum