4 ms·
Indeed. Their PCI-DSS compliance scanning service is completely useless. Service version fingerprinting only, regardless of binary patch level or actual vulns.
by vox_mollis 10y ago
Indeed. Their PCI-DSS compliance scanning service is completely useless. Service version fingerprinting only, regardless of binary patch level or actual vulns.
Yet somehow, the PCI SSC accepts their scan results as actionable for Level 1-3 compliance.
- throwanem 10y agoPCI verification is a rubber stamp all the way through, is how.