Hacker Read top | best | new | newcomments | leaders | about | bookmarklet login

I'm fairly sure that violates PCI-DSS.


sort by: page size:

Good writeup. There's absolutely no way this is not a PCI-DSS violation.

How is that even possible? it's direct PCI DSS violation! Is not there any supervising body?

That does not seem PCI compliant

That sounds shockingly non-PCI compliant.

Good point - can't believe I didn't pick that up! That's an even more obvious violation of PCI-DSS (and even the most basic security imaginable!).

Not unusual doesn't make it acceptable. It is still a PCI DSS violation.

That's what I thought it was saying too. That's a mess from a compliance and best-practices point of view :(

Or am I missing something and this would follow the PCI DSS?


And that bank is probably in violation of PCI DSS.

Wouldn't doing that be a massive PCI violation? Aren't there extensive audits for this sort of thing?

Almost certainly not PCI Compliant.

The fact that they don't mention that on main page makes me wonder if they even know what it is.

Use extreme caution.


That has to be a PCI violation. Maybe it doesn’t have any teeth. The CC networks seem lax with their rules.

Could this result in a huge fine or penalty, not least due to potential PCI DSS violation? Here in the EU, it'd be a big data protection issue as well.

Not based on my understanding of PCI DSS.

Is this not against PCI at all?

Rumors has that the next PCI-DSS revision will change that requirement.

I am going to sound contrarian, but I don't mean to be.

How does this violate PCI-DSS? The data itself is likely stored somewhere secure (who knows) – what's being displayed in the web app is the last four digits of the card and expiration date, this isn't where it's stored.

There is obviously a question of what the retention should be, but it's definitely the case that payment information can be transferred between companies.

The whole situation exudes a lack of trust, but it's not clear to me that PCI compliance is a problem here.


Don't have any experience with PCI compliance but I assume this kind of stuff _should_ remove the most idiotic security holes.

Yea, I hope PCI DSS clarifies this matter soon.

You're right if you're thinking it shouldn't be.

Nonsense. That would only be true if PCI was somehow related to security. ;-)

next

Legal | privacy