Recently there has been a lot of talk about privacy online. Its now accepted that various protocols used to secure the internet are now no longer secure and don’t give users the online privacy they would require.
SSL v3.0, TLS 1.0 and TLS 1.1 are the protocols that are open to attack, these are used to secure HTTPS traffic between a client and server. As a result PCI DSS has started to make plans to force online stores to move to TLS 1.1 but this isn’t to 2018 and TLS 1.1 is not considered secure enough.
Several payment gateways and shipping providers have already implemented their own plans to make their services secure by removing support for the insecure protocols. UPS has already disabled support for anything other than TLS 1.2. This is the current gold standard for ensuring that the traffic is secure.
Paypal have announced that in June 2016 they too will only support TLS 1.2.
So what does that mean for our customers?
So if you're not already running version 3.5.0 or greater of Cart Viper or version 3.8.0 or greater of the Event Planner module it is important you upgrade now to continue to take online payments.
Our modules were previously built with .net Framework 4.0 which does not have support to TLS 1.2. We now have had to compile them against .net 4.5.1 which does have support for TLS 1.2.
.net Framework 4.5.1 was released in 2013 so it should be already installed on your server and you won’t need to change your application pool.
The latest versions of Cart Viper be downloaded here and the Event Planner module here, so now if the perfect time to upgrade or start a new project knowing the modules are ready for the upcoming changes!