• Global community
    • Language:
      • Deutsch
      • English
      • Español
      • Français
      • Português
  • 日本語コミュニティ
    Dedicated community for Japanese speakers
  • 한국 커뮤니티
    Dedicated community for Korean speakers
Exit
Locked
1

Authorize.net SSLv3 shutdown, Poodle vulnerability - BC is not affected

Adobe Employee ,
Oct 30, 2014 Oct 30, 2014

Copy link to clipboard

Copied

Hi all,

We’ve been getting many reports over the last few days regarding the POODLE vulnerability and SSLv3 support. As you may be aware, an Internet-wide security issue, commonly referred to as POODLE, has been identified in the last two weeks - it creates a vulnerability that could allow hackers to gain access to any connection using an outdated Web browser.

Business Catalyst is not vulnerable to the POODLE vulnerability. We have disabled SSLv3 on all our servers as soon as the vulnerability news has been released. As a result of this, customers using older versions of browsers (i.e. IE 6.0) might not be able to access their sites properly.

Furthermore, we’ve been getting questions regarding our Authorize.net integration after they announced they will disable SSLv3 connections (http://community.developer.authorize.net/t5/The-Authorize-Net-Developer-Blog/Important-POODLE-Inform...).

We’d like to confirm that our Authorize.net integration won’t be affected by their change.

Thanks and regards,
Florin

TOPICS
System updates

Views

1.5K

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Contributor ,
Nov 03, 2014 Nov 03, 2014

Copy link to clipboard

Copied

Hi Florin

Does this affect any other payment gateways, including Payment Express?

Thanks

Simon

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Adobe Employee ,
Nov 04, 2014 Nov 04, 2014

Copy link to clipboard

Copied

Hi Simon,

No payment gateway integration should be affected as our servers are able to negotiate and successfully connect using TLS 1.0, 1.1 and 1.2.

Best regards,

Daniel

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
Nov 13, 2014 Nov 13, 2014

Copy link to clipboard

Copied

Good to hear that SSLv3 is disabled, but what about this ALERT I got from Meritus: We are advising all merchants and partners to disable SSL v3 on web browsers or hosts that interact with Meritus and upgrade to use Transport Layer Service (TLS). Please ask your IT department to make these changes as soon as possible, but before December 4, 2014.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
LEGEND ,
Nov 13, 2014 Nov 13, 2014

Copy link to clipboard

Copied

Just do not worry about it, everyone is issuing such warnings and BC has covered that they are not effected.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Guide ,
Nov 13, 2014 Nov 13, 2014

Copy link to clipboard

Copied

Just for clarity, BC would have been affected as I highly doubt they didn't run SSL3 as they would like to support IE6 over a HTTPs connection, just like everyone else they would have disabled it. I think it's great news, it means IE6 is now effectively killed as it doesn't support TLS by default.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
LEGEND ,
Nov 15, 2014 Nov 15, 2014

Copy link to clipboard

Copied

BC has not supported IE 7 for a while TheBCMan, let alone IE6. They put out the announcement already they are fine and not having to make any changes.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Jan 21, 2015 Jan 21, 2015

Copy link to clipboard

Copied

LATEST

Hi,

I know it's late to leave this reply, however Firefox and Chrome had removed SSL3 support in their browsers, as SSL3 is being used by a small amount of users, they were confident in turning this service off. As long as your browser is up-to-date you'll be fine.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines