in reply to Securing an API secret key

Flaws in this scenario? Other solutions?

Don't "invent" solutions, ask your credit card processor what to do, get it in writing

Replies are listed 'Best First'.
Re^2: Securing an API secret key
by Odud (Pilgrim) on Aug 29, 2012 at 09:06 UTC

    Just to back up what Anonymous Monk said I will quote Professor Dan Boneh "Be careful when using crypto: A tremendous tool, but if incorrectly implemented products will work, but may be easily attacked. Make sure to have others review your designs and code. Don’t invent your own ciphers or modes." You are inventing your own mode here I think.