4 ms·
Very cool! But unfortunately the reality is most startups never capture the first 6 numbers of credit cards if they are using a payment gateway (stripe, recurly
by brryant 12y ago
Very cool! But unfortunately the reality is most startups never capture the first 6 numbers of credit cards if they are using a payment gateway (stripe, recurly, etc). Do you have ideas on how we can access the BIN without compromising security if we're using said services?
- yookd 12y agoHi, I'm David, one of the engineers at Ribbon. If you use any payment gateway, you need to send the full credit card number from the client so the gateway can return a token that identifies the card in their vault. You can do the same and write some JS to get the first 6 numbers and send a GET request to our API without compromising security. The BIN (first 6 numbers of credit cards) is not considered the primary account number so it's safe to send (and even store).
- kirkbackus 12y agoCan I store a BIN and associate it to a customer without breaking PCI compliance?
- duskwuff 12y agoYou're allowed to store up to the first six and last four digits of a credit card number without encryption.
- bradbeattie 12y agohttps://www.pcisecuritystandards.org/documents/pci_dss_v2.pdf https://www.pcisecuritystandards.org/documents/pci_dss_v2.pd..., PCI DSS 3.3 would seem to be the most applicable section here.
- gkoberger 12y agoI use it on the client side to show a country icon and credit card issuer, and use Stripe on the backend.
- adrr 12y agoThink most startups collect BINs. Its easily to have javascript grab the first 6 digits. You already have code that validates the card with luhn check and also determine card type, grab the first 6 characters and stick it in a hidden field.