ePhilanthropy eZine
The global leader in providing training to charities for the ethical and efficient use of the Internet for philanthropic purposes through education and advocacy -- http://ephilanthropy.org

Tuesday, December 7, 2004 eZine 5 Issue 6: Helpful Quick Tip Guides Launched, 2004 Guidestar Survey, Credit Card Security, Become an eAdvocate, New ListServe Launched   VOLUME 5 ISSUE 6  
HOME
TOPICS
Learn Online and On The eTour
eZine Sponsor
News and Reports
Education
People
CONTENTS
ePhilanthropy QuickTips Guides **NEW** Keep You a Step Ahead
Job Bank: New Positions Posted, Add Your Open Position Today!
GuideStar Survey Shows Increased Support for Charity in 2004
Washington DC (Nearly SOLD OUT) - December 13, 2004
Anchorage AK (Final eTour for 2004) - December 16, 2004
NEW Opportunity!! Help Create An ePhilanthropy User Group/ Virtual Chapter In Your Area
Get spam-fighting tools including FREE anti-spam software
Increase Donations without Increasing Donors!
Six Weeks To The SUNNY Naples FL 2005 ePhilanthropy Training- January 13, 2005
Find out how Community Foundations Reduce Costs!
DonorPerfect – The All-In-One Donor Relations Solution!
Credit Card Security
Support Online Giving: Become an eAdvocate
eTour Listserve Open for Discussion
Having a Nonprofit Web Site Just Got Easier....and it's FREE!
Credit Card Security
How to Maintain a Secure Web Arena for Online Donation Processing
by David Crooke, Convio

Online marketing techniques have revolutionized the world of nonprofit organizations. As more people move online and integrate the Internet into their lives, fundraisers and nonprofits alike need to recognize the advantages of using Internet technology to streamline donation processing.

Online donation processing is an excellent way to reduce costs and manual tasks associated with direct fundraising. However, using the Internet for donation processing requires stringent security processes. Here are a few key issues to consider:

SSL Does Not Necessarily Make It Secure
Many people talk about their “secure” Web sites when they actually mean that the communication between the Web browser (such as Microsoft Internet Explorer® and Netscape®) and the Web server is encrypted using the Secure Sockets Layer (SSL), a standard set of Internet communication rules, for managing the security of message transmissions over the Internet. While using SSL is essential, it is one minor element of an overall security architecture.

People who hack, or break into, Web servers typically do not do it by tapping into connections from browsers. Instead, they do it by attacking other weak points, including the human element. In fact, about 80 percent* of successful online “break-ins” involve simply stealing passwords to gain access. Therefore, any organization should carefully consider end-to-end security processes before offering online donation processing on its Web site. 

Storing Credit Card Numbers
Another key concern is securing credit card numbers once the Web site has accepted them. Smaller e-commerce software providers are often lax about this aspect of security, so organizations should be careful to understand a provider’s security policies before using the company’s services for online transactions.

In addition, many organizations encrypt their Web databases, mistakenly believing that this protects the data. However, a hacker who breaks into a server gets not only the encrypted data, but also the decryption keys and software, enabling the hacker to obtain the card numbers. There is also the risk of a security breach if credit card data is available to staff members.

The only truly safe solution is both simple and bulletproof: Do not store credit card numbers at all. Watch for companies with donation processing capabilities that authorize credit cards in real time, and then immediately discard the card number. Follow-up transactions, including refunds or monthly donations, are processed using one-time reference codes that are tied to the nonprofit's account and useless to a fraudster. Card numbers are only stored by the payment gateway, or the system that manages transactions and connects the Internet to banking networks, whose systems are highly secure.

Fraud is Not the Issue; It’s Carding
A practice known as “carding” is a major concern for nonprofits.  Fraudsters use a low-dollar online donation to test the validity of guessed or stolen card numbers.  Although carding does not defraud the nonprofit, the organization is burdened by the administrative work required to issue a refund to the real credit card holder. Until recently, the only solution was for an organization to use software that monitored the Web site for failed transactions. Today, however, use of additional CVV2 security codes (the 3-4 digit additional numbers on credit cards) is a promising alternative. Unlike the old Address Verification System (AVS), CVV2 was designed for automated fraud protection, and is gaining ground in the United States.

In summation, strict credit card security is critical for any organization offering online donation processing on its Web site. By keeping in mind key issues when creating security strategy, organizations can help to ensure safe transactions for their online donors.

* Data from Carnegie-Mellon CERT advisory centre.

 

About the author:

David Crooke

Founder, Chief Technology Officer

Convio, Inc. 

 

David Crooke founded and acts as the chief technology officer for Convio, Inc., the leading provider of software and services to help nonprofit and individual-supported organizations use the Internet to become more effective at fundraising, mobilizing support and managing constituent relationships.

www.convio.com
[PRINTER FRIENDLY VERSION]
LETTERS

There are no letters for this article. To post your own letter, click Post Letter.

[POST LETTER]
Published by ePhilanthropy Foundation
Copyright © 2004 ePhilanthropyFoundation.Org. All rights reserved.
ePhilanthropyFoundation.Org 1101 15th Street, NW, Suite 200 Washington, DC 20005 phone: 877.536.1245 fax: 202.478.0910 email: eZine@ephilanthropy.org Copyright 2004 ePhilanthropyFoundation.Org. All rights reserved.
TELL A FRIEND
Copyright © 2002, the ePhilanthropyFoundation.Org. All rights reserved. Permission to use, copy, and/or distribute this document in whole or in part for non-commercial purposes without fee is hereby granted provided that this notice and appropriate credit to the Foundation is included in all copies.
Powered by IMN