Possible ethical dilemma

Status
Not open for further replies.

pstylesss

Platinum Member
Mar 21, 2007
2,914
0
0
I have a client who outsources his website development work to me. The current client I am doing work for wants to accept credit card transactions online via donations and a joining fee.

I informed my client that his clients easiest route would be paypal and second would be through their banks online merchant service. Apparently, they are insisting that the credit card information is emailed to them and they process it manually. Through email I have told my client that it's not secure enough. Even with SSL on the server and if they connect to the email server with SSL it's still not secure. The webserver and email server are on the same box.

I gave them the only way I would be comfortable with not using a merchant service, but the cost for me to code all that was very high and they didn't want to pay.

So, my ethical delima is whether or not I refuse to put in the code to email the CC info since I know it's not secure even though I have informed them.

So what do you guys think?
 

magomago

Lifer
Sep 28, 2002
10,973
14
76
Don't do it, especially if you have a problem with it yourself.

That said, ethics and morality seems to often be ignored in the business world.

edit:

hammer them on using an online merchant service. They exist exactly for this reason.
 

AreaCode707

Lifer
Sep 21, 2001
18,440
101
91
I would submit a written risk evaluation of their options and state that professional standards do not allow you to assume the level of risk for their preferred option. Identity theft is a PITA and standing up against a company that doesn't realize the risk at which they put their customers is a totally honorable thing to do.
 

kranky

Elite Member
Oct 9, 1999
21,014
137
106
Originally posted by: AreaCode707
I would submit a written risk evaluation of their options and state that professional standards do not allow you to assume the level of risk for their preferred option. Identity theft is a PITA and standing up against a company that doesn't realize the risk at which they put their customers is a totally honorable thing to do.

I like this idea a lot.

And please don't initiate an SSL connection if the data isn't going to be handled securely. It's like a bait-and-switch deal.
 

A Casual Fitz

Diamond Member
May 16, 2005
4,654
1,018
136
Originally posted by: AreaCode707
I would submit a written risk evaluation of their options and state that professional standards do not allow you to assume the level of risk for their preferred option. Identity theft is a PITA and standing up against a company that doesn't realize the risk at which they put their customers is a totally honorable thing to do.

:thumbsup:
 

MagnusTheBrewer

IN MEMORIAM
Jun 19, 2004
24,135
1,594
126
I'm in a dilemma in regards to your "delima." Don't add to the intarwebs problems by allowing them to create an insecure money transfer system.
 

ConstipatedVigilante

Diamond Member
Feb 22, 2006
7,671
1
0
Just say you're not willing to accept any risk of liability for people's money being at risk; they have to pay for the secure transfer or nothing.
 

Pepsei

Lifer
Dec 14, 2001
12,895
1
0
Originally posted by: ConstipatedVigilante
Just say you're not willing to accept any risk of liability for people's money being at risk; they have to pay for the secure transfer or nothing.

this
 

pstylesss

Platinum Member
Mar 21, 2007
2,914
0
0
Originally posted by: MagnusTheBrewer
I'm in a dilemma in regards to your "delima." Don't add to the intarwebs problems by allowing them to create an insecure money transfer system.

Thanks, fixed it! :thumbsup:

Originally posted by: magomago
Don't do it, especially if you have a problem with it yourself.

That said, ethics and morality seems to often be ignored in the business world.

edit:

hammer them on using an online merchant service. They exist exactly for this reason.

Originally posted by: AreaCode707
I would submit a written risk evaluation of their options and state that professional standards do not allow you to assume the level of risk for their preferred option. Identity theft is a PITA and standing up against a company that doesn't realize the risk at which they put their customers is a totally honorable thing to do.

I had done this when I outlined the program I intended to code for what they wanted.

Originally posted by: kranky
Originally posted by: AreaCode707
I would submit a written risk evaluation of their options and state that professional standards do not allow you to assume the level of risk for their preferred option. Identity theft is a PITA and standing up against a company that doesn't realize the risk at which they put their customers is a totally honorable thing to do.

I like this idea a lot.

And please don't initiate an SSL connection if the data isn't going to be handled securely. It's like a bait-and-switch deal.

That's what I tried to explain to them...

I have emails documenting all our conversations about this.
 
Status
Not open for further replies.
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |