Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Minimum knowledge for secure web payment
Search
Sponsored
·
SiteGround - Reliable hosting with speed, security, and support you can count on.
→
Yutaro Sugai
July 22, 2014
Technology
1.2k
1
Share
Minimum knowledge for secure web payment
安全なウェブ決済のために
最低限知っておいてほしいこと
WebPay meetup #1 2014/07/22
Yutaro Sugai
July 22, 2014
More Decks by Yutaro Sugai
See All by Yutaro Sugai
DevOpsDays2026 Tokyo Cross-border practices to connect "safety" and "DX" in healthcare
hokkai7go
0
290
jtf2019-hatena-sre-scrum
hokkai7go
0
12
devlove-kansai-sre-scrum
hokkai7go
0
11k
sre-lounge8
hokkai7go
6
7k
88_techbookfest5_in_omotesandorb
hokkai7go
1
160
Career Keynote at LDD '18 in Muroran
hokkai7go
1
710
What has been realized to improve maintainability at "Eight".
hokkai7go
0
1k
Serverless and tough access management
hokkai7go
1
1.5k
"1st try and team productivity"
hokkai7go
1
350
Other Decks in Technology
See All in Technology
Platform Engineering as a Product: Criteria for Improvement and Multi-Tenant Design
kumorn5s
0
450
Ruby::Boxでできること、Refinementsでできること
joker1007
2
280
AI時代から振り返るTerraform drift運用の歴史 / AI Age Reflections on the History of Terraform Drift Operations
aeonpeople
2
630
React、まだ楽しくて草
uhyo
7
3.6k
AIガバナンス実践 - 生成AIコネクタのデータ漏洩リスクと実務対策
knishioka
0
150
自称宇宙最速で不合格となったAIP-C01にリベンジを果たすべくAIで問題集アプリを作ってみた。
yama3133
0
260
JEP 522 Deep Dive - G1 GC同期コスト削減によるスループット向上を徹底検証&解説
tabatad
1
530
A Harness for Behaviour: how to get AI to generate code that does what we intend, or "TDD in the age of AI"
xpmatteo
1
530
20260528_生成AIを専属DSに_Howの次にすべきことを考える
doradora09
PRO
0
270
コードレビューを制するチームがソフトウェアデリバリーのフローを制す / Beyond Code Review: Distributing Its Responsibilities Across the SDLC
mtx2s
3
560
Java正規表現エンジン(NFA)の仕組みと パフォーマンスを維持するための最適化手法
takeuchi_132917
0
160
Terraformモジュールは、なぜ「魔境」化するのか
hayama17
1
140
Featured
See All Featured
Exploring the relationship between traditional SERPs and Gen AI search
raygrieselhuber
PRO
2
4k
We Analyzed 250 Million AI Search Results: Here's What I Found
joshbly
1
1.3k
AI Search: Where Are We & What Can We Do About It?
aleyda
0
7.5k
Automating Front-end Workflow
addyosmani
1370
210k
Max Prin - Stacking Signals: How International SEO Comes Together (And Falls Apart)
techseoconnect
PRO
0
170
Building a Scalable Design System with Sketch
lauravandoore
463
34k
HU Berlin: Industrial-Strength Natural Language Processing with spaCy and Prodigy
inesmontani
PRO
0
390
Git: the NoSQL Database
bkeepers
PRO
432
67k
Cheating the UX When There Is Nothing More to Optimize - PixelPioneers
stephaniewalter
287
14k
Jamie Indigo - Trashchat’s Guide to Black Boxes: Technical SEO Tactics for LLMs
techseoconnect
PRO
0
150
svc-hook: hooking system calls on ARM64 by binary rewriting
retrage
2
280
Introduction to Domain-Driven Design and Collaborative software design
baasie
1
810
Transcript
҆શͳΣϒܾࡁͷͨΊʹ ࠷ݶ͓͍ͬͯͯ΄͍͜͠ͱ Yutaro Sugai <
[email protected]
> @hokkai7go
ϖΠʂ (ָ͠ΜͰ·͔͢)
҆શͳΣϒܾࡁͷͨΊʹ ࠷ݶ͓͍ͬͯͯ΄͍͜͠ͱ Yutaro Sugai <
[email protected]
> @hokkai7go
@hokkai7go ! WebPay ɾαʔό܈ͷӡ༻ ɾPCIDSSͳͲηΩϡϦςΟج४ͷ४ڌ ! ݸਓ ɾ֤छRubyܥΧϯϑΝϨϯεͷϨϙʔτ൝ ɾΔͼ·ฤू ɾChef࣮ફೖॻ͖·ͨ͠
PCIDSSͬͯ·͔͢ʁ
PCIDSSͱ ΫϨδοτΧʔυใ࿙Ӯࢭͷ ͨΊͷࠃࡍηΩϡϦςΟج४ ΫϨδοτΧʔυใΛऔΓѻ͏ શͯͷࣄۀऀαʔϏεϓϩόΠ μɺ͜ͷඪ४ʹ४ڌ͢Δඞཁ͕ ͋Γ·͢ɻ(േଇͳ͠)
PCIDSSͱ ܾࡁࣄۀऀ͚ͩͰͳ͘ AWSͳͲͷαʔϏεϓϩόΠμ͕ ४ڌ͢Δྫ͕૿͍͑ͯΔ
Χʔυ൪߸࿙Ӯͷ ࡾେϦεΫϙΠϯτ
ॲཧ ૹ อଘ
4242#4242#4242#4242 ૹ
4242#4242#4242#4242 ૹ
4242#4242#4242#4242 ૹɾॲཧ
4242#4242#4242#4242 อଘ
ૹ
PCIDSS ૹ࣌҉߸ԽΛཁٻ
”ΦʔϓϯͳެڞωοτϫʔΫܦ༝Ͱػີ ੑͷߴ͍ΧʔυձһσʔλΛૹ͢Δ ߹ɺҎԼͷΑ͏ͳɺڧྗͳ҉߸ԽͱηΩϡ ϦςΟϓϩτίϧʢSSL/TLSɺIPSECɺ SSHͳͲʣΛ༻ͯ͠อޢ͢Δɻ” - PCIDSS ཁ݅ͱηΩϡϦςΟධՁखॱόʔδϣϯ3.0 ΑΓൈਮ
҉߸ԽͤͣʹΧʔυ൪߸ ͷૹ͍ͯ͠·ͤΜ͔ʁ
ੜͷΧʔυ൪߸ΛαʔόͰ ड͚ͱΓͨ͘ͳ͍Ͱ͢ΑͶ
Έͳ͞Μ͕Χʔυ൪߸Λۃྗѻ Θͳ͍͍ͯ͘Α͏ʹɺτʔΫϯ ܾࡁͷΈΛ༻ҙ͍ͯ͠·͢
ɾΫϥΠΞϯταΠυτʔΫϯ ɾαʔόαΠυτʔΫϯ
ΫϥΠΞϯταΠυτʔΫϯͷར ʮॲཧʯʮૹʯʮอଘʯͷ ͯ͢Λճආ͢Δ͜ͱ͕Ͱ͖·͢
https://webpay.jp/docs/payments_with_token
ΫϥΠΞϯταΠυτʔΫϯΛΘͳ͍ ɾʮॲཧʯʮૹʯΛආ͚ΒΕͳ͍ ɾੜͷΧʔυ൪߸Λѻ͏ϦεΫ ɹɾܦ࿏্ͷϩάʹΧʔυ൪߸͍ͬͯ·ͤΜ͔ʁ ɹɾʮॲཧʯޙͷϝϞϦ҆શͰ͔͢ʁ
ʮॲཧʯʮૹʯΛߦ͏͜ͱϦεΫͰ͢ɻ ΫϥΠΞϯταΠυτʔΫϯΛར༻ͯ͠ ආ͚Δ͜ͱΛ͓͢͢Ί͠·͢ɻ
҆શͳΣϒܾࡁͷͨΊʹ ɾSSLͷ༻(αΠτؙ͝ͱ or ࠷Ͱܾࡁϖʔδ) ɾదͳΤϥʔϋϯυϦϯά ɾෆཁͳΧʔυใͷഁغ