5 ms·
"Let's talk about that CVV for a moment. ... PCI DSS is very clear about how the CVV (or CVV2 as it is these days) should be stored ... It shouldn't be stored a
by just_observing 10y ago
"Let's talk about that CVV for a moment. ... PCI DSS is very clear about how the CVV (or CVV2 as it is these days) should be stored ... It shouldn't be stored and that's what makes this breach such a big issue. Violation of PCI DSS guidelines can lead to pretty serious fines and even loss of merchant facilities; the card providers take this very seriously.
It checked out - this is the CVV."
- pjc50 10y agoWhile we're on the subject, how do Amazon get a pass for not making the user re-enter the CVV for every transaction?
- chillydawg 10y agoWhen you're amazon, you can negotiate anything. They're probably the single biggest online credit card merchant.
- TimWolla 10y agoAFAIK the CVV is not required to perform a transaction. It's just that you take the hit in case a fraud occurs when you don't check the CVV.
- devicenull 10y agoDepends on your merchant account I believe. We tokenize them somehow, and can do further transactions by referencing the first transaction.
- arcdigital 10y agoYou don't need to make the user enter the CVV for any transaction, it just helps with a lower fee and to shift the chargeback liability.
- okiedipshiz 10y agoI learned this the first time I was implementing a system. They gave me the guidelines and I was like, good deal, no CVV. Pretty easy but how many developers actually ever see real requirements?
- randomnerdiness 10y agoThat's because you have a brain. You wouldn't believe some of the stuff I've seen people try to use. So much copypasta, often with just enough changed to be hacked into a customer's system.