4 ms·
The credit agencies are supposed to protect cardholders via PCI DSS audits (see https://www.pcisecuritystandards.org/pdfs/pci_fs_data_storage.pdf https://www.pc
by checker 7y ago
The credit agencies are supposed to protect cardholders via PCI DSS audits (see https://www.pcisecuritystandards.org/pdfs/pci_fs_data_storage.pdf https://www.pcisecuritystandards.org/pdfs/pci_fs_data_storag...).
This is definitely non-compliant. Obviously this system is broken.
Additionally, I don't understand why companies continue to roll their own payment processing rather than paying a service that knows how to do it. I guess it seems easy...
- tsukurimashou 7y agoWell if you can make more profit, have all the advantages without being PCI DSS compliant. Why would you not roll your own payment processing? Since nothing happens apparently when the data of your customers get "breached"
- AdieuToLogic 7y ago> Why would you not roll your own payment processing? There are various "financial hammers" these types of breaches will induce, depending on the network (Visa, MasterCard, etc.). Plus, processors (the banks) will put the liability onto Merchants which are shown to have violated thier ToS. Storing PAN's in clear text (or at all in some cases) is certain to trigger one or both of these ramifications.
- heavenlyblue 7y agoWhat about being “big enough that they will discount all of these ramifications”?
- nineears 7y agoPCI DSS is a program of the card associations to protect the issuing banks from fraud losses. Merchants have difficulty complying so it ends up as a balancing act between keeping the wheels of commerce moving and preventing fraud. Fully outsourced payment solutions are a good fit for some business models but not for others.
- AdieuToLogic 7y agoGreat post. One thing I would add is that PCI DSS is also applicable for ISO's as well VAR's which operate payment processing gateways.