Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

But your application server can strip out spaces and dashes before you send the number to the gateway. Right?


Of course - We do it.

Wondering if anyone uses a payment gateway which prohibits this..


how could they possibly even know you've already stripped out non-numeric characters?


Audit. Our code is audited and certified by a security firm contracted by our merchant service provider (read bank). They don't have any such anti-transformation provision, but I'm curious to know if any payment gateway does.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: