Paypal & Transport Layer Security

  • Posts: 21
  • Thank you received: 2
10 years 9 months ago #179228

I've just received the following email from Paypal:

On 14 October 2014, details were released about a vulnerability to version 3 of Secure Sockets Layer (SSL 3.0). Since that time, PayPal has been hard at work to mitigate any potential impact to our consumers and merchant customers.

To help mitigate risk associated with this vulnerability, PayPal will discontinue support for SSL 3.0 on 3 December 2104 at 8:01 a.m. Greenwich Mean Time. Unfortunately, this necessary step may cause compatibility problems resulting in the inability for customers to pay with PayPal on your site or other processing issues.

We wouldn’t have been able to extend our support of SSL 3.0 to 3 December 2014, at 8:01 a.m. GMT if we hadn’t also been able to take significant steps to migrate the risk of this vulnerability for our customers. We want to assure our customers we have seen no evidence that the SSL 3.0 issue has led to any compromise of security at PayPal.

Keeping our customers’ accounts, data and money secure is PayPal’s top priority and a guiding principle when we make challenging decisions, like this one.

We’re here to help our merchants through this process. We’ve put together a comprehensive Merchant Response Guide to ensure systems are secure from this vulnerability.

What do I need to do?

If you don’t manage website integrations for your business, we strongly encourage you to work with your website service partner (developer, hosting company or e-commerce platform, etc.) and share the Merchant Response Guide, which provides the basic guidelines on how to update to Transport Layer Security (TLS). If your website service has questions or need support, advise them to contact our Merchant Technical Support.


Does this affect the operation of Hikashop? Since all my payments are processed via Hikashop and Paypal, I want to ensure that everything will continue to work. :)

Please Log in or Create an account to join the conversation.

  • Posts: 26264
  • Thank you received: 4043
  • MODERATOR
10 years 9 months ago #179229

Hi,

It does not affect HikaShop.
It will continue to work.

Regards,


Jerome - Obsidev.com
HikaMarket & HikaSerial developer / HikaShop core dev team.

Also helping the HikaShop support team when having some time or couldn't sleep.
By the way, do not send me private message, use the "contact us" form instead.

Please Log in or Create an account to join the conversation.

  • Posts: 1
  • Thank you received: 0
10 years 8 months ago #181728

Hi Jerome,

I am using Hikashop version 1.5.3. Does this affect the operation of Hikashop paypal. Thank you

Please Log in or Create an account to join the conversation.

  • Posts: 26264
  • Thank you received: 4043
  • MODERATOR
10 years 8 months ago #181738

Hi,

Since a very long time, the HikaShop paypal plugin is using a SSL negotiation in order to determine which version it should use.
We do not force SSLv3 (which have the POODLE) issue.

When Paypal deactive SSLv3 in the sandbox, we made some tests in order to be sure that the plugin is still compatible and it worked.
Since November 3 the paypal sandox have the modification that will be put in production on December 3.
You can create a new paypal method in your website in order to perform a sandbox test. If you still got the notification you will be sure that it will continue to work properly (and then unpublish the sandbox method).

Regards,


Jerome - Obsidev.com
HikaMarket & HikaSerial developer / HikaShop core dev team.

Also helping the HikaShop support team when having some time or couldn't sleep.
By the way, do not send me private message, use the "contact us" form instead.
The following user(s) said Thank You: suhas

Please Log in or Create an account to join the conversation.

Time to create page: 0.060 seconds
Powered by Kunena Forum