Пришло в интернет-магазин такое вот письмо, мне нужна грамотная консультация о том, нужно ли предпринимать какие-то действия:
Immediate Action Required
%%First%% %%Last%%,
On Tuesday, October 14, 2014, details were released about a vulnerability to version 3 of Secure Sockets Layer (SSL 3.0). SSL provides encryption to protect your information from attackers. Many websites and internet businesses are reliant on SSL 3.0.
Since many merchants rely on SSL 3.0 to connect to PayPal, we have not immediately turned it off. However, to help mitigate risk associated with this vulnerability, we're urging our merchants to disable SSL 3.0 as soon as possible. Unfortunately, this necessary step may cause compatibility problems resulting in the inability for customers to pay with PayPal on your site or other processing issues that we're still trying to identify.
We've put together a comprehensive Merchant Response Guide to ensure systems are secure from this vulnerability.
What do I need to do?
Test your current integration against the PayPal Sandbox
If you're integrated through a Partner, no further action is required on your part.
If you're directly integrated with PayPal, follow these steps:
i. Point your test environment to our Sandbox (
ii. Check your log files. If you're using SSL 3.0, you'll need to configure your secure connection to use Transport Layer Service (TLS). The Merchant Response Guide provides more information on determining if you're using SSL 3.0.
Update to Transport Layer Service (TLS)
We're urging all of our customers to disable SSL 3.0 on hosts interacting with PayPal as soon as possible and upgrade to TLS.
Refer to the Merchant Response Guide for a table that provides basic guidelines on how to update to TLS using common languages and connection methods. Your exact settings may vary.
Issue new credentials
After you've successfully tested and upgraded to TLS, we recommend that you reissue and download new Application Program Interface ( API) credentials for any API request. This step is recommended, but not required. Please make a risk-based decision for your business and customers.
i. If you're using Certificate authentication, no action is required.
ii. If you're using Signature authentication, see
iii. If you're using OAuth authentication, see:
Thank you for your prompt attention to this issue and understanding of our approach. Though we recognize this necessary step may cause compatibility issues, we can't stress enough that this short-term inconvenience is heavily outweighed by our joint promise to our respective customers that we will keep their financial details safe. We plan to keep our customers up to date on how we are addressing this issue via the appropriate channels, including PayPal Forward, our Twitter handle, Customer Service and for merchants, through our Merchant Services team. We appreciate your patience and understanding as we work around the clock to better serve you and keep you safe.
Please do not reply to this email. We are unable to respond to inquiries sent to this address. For immediate answers to your questions, visit our help center by clicking Help on any PayPal page.
© 2014 PayPal, Inc. All rights reserved. PayPal is located at 2211 N. First St., San Jose, CA 95131.
Yours sincerely,
Gemma
PayPal