Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Minimum knowledge for secure web payment
Search
Yutaro Sugai
July 22, 2014
Technology
1
1.1k
Minimum knowledge for secure web payment
安全なウェブ決済のために
最低限知っておいてほしいこと
WebPay meetup #1 2014/07/22
Yutaro Sugai
July 22, 2014
Tweet
Share
More Decks by Yutaro Sugai
See All by Yutaro Sugai
devlove-kansai-sre-scrum
hokkai7go
0
11k
sre-lounge8
hokkai7go
6
6.6k
88_techbookfest5_in_omotesandorb
hokkai7go
1
110
Career Keynote at LDD '18 in Muroran
hokkai7go
1
580
What has been realized to improve maintainability at "Eight".
hokkai7go
0
940
Serverless and tough access management
hokkai7go
1
1.4k
"1st try and team productivity"
hokkai7go
1
310
Technology to support Eight, Infrastructure part
hokkai7go
0
600
AWS and Serverless and Monitoring
hokkai7go
1
2.2k
Other Decks in Technology
See All in Technology
ソフトウェアプロジェクトの成功率が上がらない原因-「社会価値を考える」ということ-
ytanaka5569
0
130
アプリケーション固有の「ロジックの脆弱性」を防ぐ開発者のためのセキュリティ観点
flatt_security
28
10k
どっちの API SHOW?SharePoint 開発における SharePoint REST API Microsoft Graph API の違い / Which API show? Differences between Microsoft Graph API and SharePoint REST API
karamem0
0
110
Multitenant 23ai の全貌 - 機能・設計・実装・運用からマイクロサービスまで
oracle4engineer
PRO
2
120
ソフトウェア開発現代史: なぜ日本のソフトウェア開発は「滝」なのか?製造業の成功体験とのギャップ #jassttokyo
takabow
2
1.6k
SpannerとAurora DSQLの同時実行制御の違いに想いを馳せる
masakikato5
0
570
17年のQA経験が導いたスクラムマスターへの道 / 17 Years in QA to Scrum Master
toma_sm
0
400
技術的負債を正しく理解し、正しく付き合う #phperkaigi / PHPerKaigi 2025
shogogg
7
1.8k
Explainable Software Engineering in the Public Sector
avandeursen
0
360
バクラクでのSystem Risk Records導入による変化と改善の取り組み/Changes and Improvement Initiatives Resulting from the Implementation of System Risk Records
taddy_919
0
220
「ラベルにとらわれない」エンジニアでいること/Be an engineer beyond labels
kaonavi
0
120
スケールアップ企業のQA組織のバリューを最大限に引き出すための取り組み
tarappo
4
930
Featured
See All Featured
A better future with KSS
kneath
238
17k
Performance Is Good for Brains [We Love Speed 2024]
tammyeverts
8
700
Optimising Largest Contentful Paint
csswizardry
35
3.2k
Why Our Code Smells
bkeepers
PRO
336
57k
Build The Right Thing And Hit Your Dates
maggiecrowley
34
2.6k
Unsuck your backbone
ammeep
670
57k
A Modern Web Designer's Workflow
chriscoyier
693
190k
RailsConf 2023
tenderlove
29
1k
VelocityConf: Rendering Performance Case Studies
addyosmani
328
24k
XXLCSS - How to scale CSS and keep your sanity
sugarenia
248
1.3M
Why You Should Never Use an ORM
jnunemaker
PRO
55
9.3k
Visualization
eitanlees
146
16k
Transcript
҆શͳΣϒܾࡁͷͨΊʹ ࠷ݶ͓͍ͬͯͯ΄͍͜͠ͱ Yutaro Sugai <
[email protected]
> @hokkai7go
ϖΠʂ (ָ͠ΜͰ·͔͢)
҆શͳΣϒܾࡁͷͨΊʹ ࠷ݶ͓͍ͬͯͯ΄͍͜͠ͱ Yutaro Sugai <
[email protected]
> @hokkai7go
@hokkai7go ! WebPay ɾαʔό܈ͷӡ༻ ɾPCIDSSͳͲηΩϡϦςΟج४ͷ४ڌ ! ݸਓ ɾ֤छRubyܥΧϯϑΝϨϯεͷϨϙʔτ൝ ɾΔͼ·ฤू ɾChef࣮ફೖॻ͖·ͨ͠
PCIDSSͬͯ·͔͢ʁ
PCIDSSͱ ΫϨδοτΧʔυใ࿙Ӯࢭͷ ͨΊͷࠃࡍηΩϡϦςΟج४ ΫϨδοτΧʔυใΛऔΓѻ͏ શͯͷࣄۀऀαʔϏεϓϩόΠ μɺ͜ͷඪ४ʹ४ڌ͢Δඞཁ͕ ͋Γ·͢ɻ(േଇͳ͠)
PCIDSSͱ ܾࡁࣄۀऀ͚ͩͰͳ͘ AWSͳͲͷαʔϏεϓϩόΠμ͕ ४ڌ͢Δྫ͕૿͍͑ͯΔ
Χʔυ൪߸࿙Ӯͷ ࡾେϦεΫϙΠϯτ
ॲཧ ૹ อଘ
4242#4242#4242#4242 ૹ
4242#4242#4242#4242 ૹ
4242#4242#4242#4242 ૹɾॲཧ
4242#4242#4242#4242 อଘ
ૹ
PCIDSS ૹ࣌҉߸ԽΛཁٻ
”ΦʔϓϯͳެڞωοτϫʔΫܦ༝Ͱػີ ੑͷߴ͍ΧʔυձһσʔλΛૹ͢Δ ߹ɺҎԼͷΑ͏ͳɺڧྗͳ҉߸ԽͱηΩϡ ϦςΟϓϩτίϧʢSSL/TLSɺIPSECɺ SSHͳͲʣΛ༻ͯ͠อޢ͢Δɻ” - PCIDSS ཁ݅ͱηΩϡϦςΟධՁखॱόʔδϣϯ3.0 ΑΓൈਮ
҉߸ԽͤͣʹΧʔυ൪߸ ͷૹ͍ͯ͠·ͤΜ͔ʁ
ੜͷΧʔυ൪߸ΛαʔόͰ ड͚ͱΓͨ͘ͳ͍Ͱ͢ΑͶ
Έͳ͞Μ͕Χʔυ൪߸Λۃྗѻ Θͳ͍͍ͯ͘Α͏ʹɺτʔΫϯ ܾࡁͷΈΛ༻ҙ͍ͯ͠·͢
ɾΫϥΠΞϯταΠυτʔΫϯ ɾαʔόαΠυτʔΫϯ
ΫϥΠΞϯταΠυτʔΫϯͷར ʮॲཧʯʮૹʯʮอଘʯͷ ͯ͢Λճආ͢Δ͜ͱ͕Ͱ͖·͢
https://webpay.jp/docs/payments_with_token
ΫϥΠΞϯταΠυτʔΫϯΛΘͳ͍ ɾʮॲཧʯʮૹʯΛආ͚ΒΕͳ͍ ɾੜͷΧʔυ൪߸Λѻ͏ϦεΫ ɹɾܦ࿏্ͷϩάʹΧʔυ൪߸͍ͬͯ·ͤΜ͔ʁ ɹɾʮॲཧʯޙͷϝϞϦ҆શͰ͔͢ʁ
ʮॲཧʯʮૹʯΛߦ͏͜ͱϦεΫͰ͢ɻ ΫϥΠΞϯταΠυτʔΫϯΛར༻ͯ͠ ආ͚Δ͜ͱΛ͓͢͢Ί͠·͢ɻ
҆શͳΣϒܾࡁͷͨΊʹ ɾSSLͷ༻(αΠτؙ͝ͱ or ࠷Ͱܾࡁϖʔδ) ɾదͳΤϥʔϋϯυϦϯά ɾෆཁͳΧʔυใͷഁغ