5 ms·
I spent almost 4 years working at a PCI level 1 compliant company that handled subscriptions. It's really a joke the lack of security these bitcoin "banks" hav
by hijinks 11y ago
I spent almost 4 years working at a PCI level 1 compliant company that handled subscriptions.
It's really a joke the lack of security these bitcoin "banks" have around their vaults. Our PCI auditor wouldn't pass us if he audited our firewall and noticed the crypto servers that stored the credit cards had outbound access to anything other then the 1 vlan that acted as a API layer from those servers and the banks.
These companies should really just follow PCI and start there.
- threeseed 11y agoIt is getting beyond a joke. The US government et al should really classify these as banks and force them to address the same privacy, disclosure, fraud prevention etc regulations. The potential of Bitcoin as something your grandparents could one day use is constantly being undermined by these cowboy operators.
- Lazare 11y ago1) Nothing is stopping you from refusing to deal with any Bitcoin exchange that is not audited to adhere to PCI 1 standards as adapted to deal with Bitcoins. If no such exchange exists, nothing is starting you from starting one. 2) I think far more damage is being done to Bitcoin by the political fighting and poor technical decisions of the core developers. Bitcoin weathered Mt Gox, it can weather Cryptsy.
- noir_lord 11y agoNot in payment industry, but side project requires heavy security, any good guides to PCI auditing, I see lots of fluff when I search and the auditors I've run into in the past have been at best a bit of a joke :)