Credit card details can be safely sent with SSL, but once stored
on the server they are vulnerable to outsiders hacking into the
server and accompanying network. A PCI (peripheral component interconnect:
hardware) card is often added for protection, therefore, or another
approach altogether is adopted: SET (Secure Electronic Transaction).
Developed by Visa and Mastercard, SET uses PKI for privacy, and
digital certificates to authenticate the three parties: merchant,
customer and bank. More importantly, sensitive information is
not seen by the merchant, and is not kept on the merchant's server.