I'm the wet blanket of despair... It's very good that you're asking. It's kinda bad that you're trying. There are many ways to mess this stuff up and doing it for a real live social-security/bank-account site the first time out of the gate is what I would call a really bad idea. Here is a partial list of concerns and ideas-
Good luck and stay scared. It makes more secure apps.
Update: changed PCI link to the one grep provided; it's better. Update:update: removed a redundant/awkward sentence.
Update: added OWASP and HttpOnly notes.
In reply to Re: collecting sensitive data
by Your Mother
in thread collecting sensitive data
by casimo
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |