Reply
Contributor
Posts: 31
Registered: ‎03-21-2013

CIM security concern

I am adding CIM to my account and will use it for recurring billing.

 

With CIM in place, I have heightened concerns about the vulnerability of the Authorize.net merchant login portal. If somebody breaks in with a bad intent they could do a lot of more damage now (like creating transactions) than what was possible before. We use best security practices to protect passwords but this is not sufficient in my opinion.

 

Is there any way to require more secure access to the Authorize.net portal (like two factor authentication or IP restricted ?)

 

 

Administrator Administrator
Administrator
Posts: 563
Registered: ‎08-03-2011

Re: CIM security concern

Hi Christophe,

 

Authorize.Net does not currently offer 2-factor authentication or IP address access restrictions. We enforce a strict password policy and encourage you to follow the best practices outlined in that policy found here: http://www.authorize.net/resources/files/PasswordPolicy.pdf.

 

Thanks,

Joy

Member
Posts: 1
Registered: ‎01-24-2015

Re: CIM security concern

Is there any update on this? 

 

We use CIM as well. With such valuable information on hand there seems like quite a bit of potential for damage. 

 

We've ensured that all other elements of our billing system require 2-factor authentication. Would be very nice to see this on top of the password policies that you enforce. 

Posts: 2,765
Topics: 57
Kudos: 245
Blog Posts: 67
Registered: ‎12-05-2011

Re: CIM security concern

 Hello @Potter 

 

You are welcome to post this as a new feature using our Ideas forum. This will allow others to vote on and make suggestions to improve the request.

Richard

Contributor
Posts: 31
Registered: ‎03-21-2013

Re: CIM security concern

You can vote for this on the Ideas board.

Posts: 2,765
Topics: 57
Kudos: 245
Blog Posts: 67
Registered: ‎12-05-2011

Re: CIM security concern

Thanks @Christophe for creating the new product idea.

 

Richard

Highlighted
Contributor
Posts: 31
Registered: ‎03-21-2013

Re: CIM security concern

This is a gentle reminder to investigate two-factor authentication. This is a critical security issue for companies using CIM. Is this feature on the way ?

Thank you

 

 

Contributor
Posts: 31
Registered: ‎03-21-2013

Re: CIM security concern

I opened this request for two-factor authentication almost 5 years ago! and also entered in the "Ideas" section:

https://community.developer.authorize.net/t5/Ideas/Authorize-net-portal-2-factor-authentication/idi-...

 

It was marked as 'accepted' but nothing happened.

 

It is 2018, how can a portal to control payments and credit cards rely solely on username/password ? This is reckless.

 

Posts: 333
Kudos: 59
Solutions: 36
Registered: ‎03-13-2017

Re: CIM security concern

Hi @Christophe

 

Thanks for your feedback .

We have Merchant Interface refresh planned in FY 18 and this will  be addressed in it . 

 

 





Send feedback at developer_feedback@authorize.net