<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CIM security concern in Integration and Testing</title>
    <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/33728#M18232</link>
    <description>&lt;P&gt;Hi &lt;SPAN class="UserName lia-user-name"&gt;&lt;A id="link_12" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/13401" target="_self"&gt;&lt;SPAN&gt;Christophe&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Authorize.Net does not currently offer 2-factor authentication or IP address access restrictions. We enforce a strict password policy and encourage you to follow the best practices outlined in that policy found here:&amp;nbsp;&lt;SPAN&gt;&lt;A title="http://www.authorize.net/resources/files/PasswordPolicy.pdf" href="http://www.authorize.net/resources/files/PasswordPolicy.pdf" target="_blank"&gt;http://www.authorize.net/resources/files/PasswordPolicy.pdf.&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Joy&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Mar 2013 21:13:26 GMT</pubDate>
    <dc:creator>Joy</dc:creator>
    <dc:date>2013-03-27T21:13:26Z</dc:date>
    <item>
      <title>CIM security concern</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/33651#M18158</link>
      <description>&lt;P&gt;I am adding CIM to my account and will use it for recurring billing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With CIM in place, I have heightened concerns about the vulnerability of the Authorize.net merchant login portal. If somebody breaks in with a bad intent they could do a lot of more damage now (like creating transactions) than what was possible before. We use best security practices to protect passwords but this is not sufficient in my opinion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way to require more secure access to the Authorize.net portal (like two factor authentication or IP restricted ?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Mar 2013 08:15:11 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/33651#M18158</guid>
      <dc:creator>Christophe</dc:creator>
      <dc:date>2013-03-23T08:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: CIM security concern</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/33728#M18232</link>
      <description>&lt;P&gt;Hi &lt;SPAN class="UserName lia-user-name"&gt;&lt;A id="link_12" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/13401" target="_self"&gt;&lt;SPAN&gt;Christophe&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Authorize.Net does not currently offer 2-factor authentication or IP address access restrictions. We enforce a strict password policy and encourage you to follow the best practices outlined in that policy found here:&amp;nbsp;&lt;SPAN&gt;&lt;A title="http://www.authorize.net/resources/files/PasswordPolicy.pdf" href="http://www.authorize.net/resources/files/PasswordPolicy.pdf" target="_blank"&gt;http://www.authorize.net/resources/files/PasswordPolicy.pdf.&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Joy&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2013 21:13:26 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/33728#M18232</guid>
      <dc:creator>Joy</dc:creator>
      <dc:date>2013-03-27T21:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: CIM security concern</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/49467#M25040</link>
      <description>&lt;P&gt;Is there any update on this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use CIM as well. With such valuable information on hand there seems like quite a bit of potential for damage.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We've ensured that all other elements of our billing system require 2-factor authentication. Would be very nice to see this on top of the password policies that you enforce.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jan 2015 15:53:33 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/49467#M25040</guid>
      <dc:creator>Potter</dc:creator>
      <dc:date>2015-01-24T15:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: CIM security concern</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/49468#M25041</link>
      <description>&lt;P&gt;&amp;nbsp;Hello &lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/17889"&gt;@Potter&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are welcome to post this as a new feature using our &lt;A href="https://community.developer.cybersource.com/t5/Ideas/idb-p/ideas" target="_blank"&gt;Ideas forum&lt;/A&gt;. This will allow others to vote on and make suggestions to improve the request.&lt;BR /&gt;&lt;BR /&gt;Richard&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jan 2015 16:39:48 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/49468#M25041</guid>
      <dc:creator>RichardH</dc:creator>
      <dc:date>2015-01-24T16:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: CIM security concern</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/50493#M25933</link>
      <description>&lt;P&gt;You can&amp;nbsp;&lt;A href="https://community.developer.cybersource.com/t5/Ideas/Authorize-net-portal-2-factor-authentication/idi-p/50492" target="_self"&gt;vote for this&lt;/A&gt; on the Ideas board.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2015 14:50:02 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/50493#M25933</guid>
      <dc:creator>Christophe</dc:creator>
      <dc:date>2015-04-30T14:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: CIM security concern</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/50496#M25936</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/13401"&gt;@Christophe&lt;/a&gt;&amp;nbsp;for creating the new product idea.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Richard&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2015 15:14:11 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/50496#M25936</guid>
      <dc:creator>RichardH</dc:creator>
      <dc:date>2015-04-30T15:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: CIM security concern</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/55797#M30635</link>
      <description>&lt;P&gt;This is a gentle reminder to investigate two-factor authentication. This is a critical security issue for companies using CIM. Is this feature on the way ?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2016 16:32:42 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/55797#M30635</guid>
      <dc:creator>Christophe</dc:creator>
      <dc:date>2016-09-21T16:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: CIM security concern</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/60955#M35464</link>
      <description>&lt;P&gt;I opened this request for two-factor authentication almost 5 years ago! and also entered in the "Ideas" section:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.developer.authorize.net/t5/Ideas/Authorize-net-portal-2-factor-authentication/idi-p/50492" target="_blank"&gt;https://community.developer.authorize.net/t5/Ideas/Authorize-net-portal-2-factor-authentication/idi-p/50492&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It was marked as 'accepted' but nothing happened.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is 2018, how can a portal to control payments and credit cards rely solely on username/password ? This is reckless.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 14:11:32 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/60955#M35464</guid>
      <dc:creator>Christophe</dc:creator>
      <dc:date>2017-12-22T14:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: CIM security concern</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/60958#M35466</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/13401"&gt;@Christophe&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your feedback .&lt;/P&gt;
&lt;P&gt;We have Merchant Interface refresh planned in FY 18 and this&amp;nbsp;will&amp;nbsp; be addressed in it .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 17:42:48 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/60958#M35466</guid>
      <dc:creator>Anurag</dc:creator>
      <dc:date>2017-12-22T17:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: CIM security concern</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/70836#M43547</link>
      <description>&lt;P&gt;So the enhancement was planned for 2018 according to the latest post, and we are in 2020. I opened the request 7 years ago.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the meantime, many websites have two-factor. Even my daughter's school website has two-factor available. It's so easy to implement with many kits available, for example from Twilio.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am a fan of Authorize.net, but we may walk out because compliance absolutely requires two-factor. Please get your act together!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 02:39:30 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-security-concern/m-p/70836#M43547</guid>
      <dc:creator>Christophe</dc:creator>
      <dc:date>2020-02-28T02:39:30Z</dc:date>
    </item>
  </channel>
</rss>

