6 ms·
> PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these iss
by ailideex 7y ago
> PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed.
Quote from your source:
> If your scan fails, you must schedule a rescan within 30 days to prove that the critical, high-risk or medium-risk vulnerabilities have been patched.
Scan in this sentence refers to "a PCI DSS external scan".
The list of approved vendors that can conduct PCI DSS external scans can be found here: https://www.pcisecuritystandards.org/assessors_and_solutions/approved_scanning_vendors https://www.pcisecuritystandards.org/assessors_and_solutions...
Please find cybernews' certificate number there and quote it for us, I have looked and can't find it.
I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong.
And even if they were an approved scanning vendor, from what little I know about PCI-DSS, these scans are part of larger process - so even if they were an approved scanning vendor the scan failure would still have had to be part of the larger process for this 30 day limit to apply.
I could go on and on about how much I hate PayPal and random other things, but just because I don't like something does not quite justify making false claims about it.
- rasengan 7y agoHackerOne states they are a PCI-DSS auditor approved organization [1]. [1] https://www.hackerone.com/product/challenge https://www.hackerone.com/product/challenge
- empath75 7y agoYeah but someone reporting a vulnerability to HackerOne is not the same as HackerOne reporting it. Otherwise you could just spam HackerOne with reports and remove someone’s compliance.
- ailideex 7y ago> HackerOne states they are a PCI-DSS auditor approved organization Not anywhere on the page you linked. And a "PCI-DSS auditor approved organization" is not a "PCI-DSS approved scanning vendor" which if they were you could just quote the certificate number instead of link to HackerOne. ---- EDIT: I guess you are referring to this: > Meet penetration testing requirements for PCI DSS and SOC2 Type II compliance certifications with our auditor-approved penetration testing methodology and Security Assessment Report. This in no way is the same as claiming "we are a PCI-DSS auditor approved organization". Which again, would be irrelevant if it was the case. ---- Further, if you read the article, it is clear the "We" does not refer to "HackerOne". > When we pushed the HackerOne staff for clarification on these issues, they removed points from our Reputation scores, relegating our profiles to a suspicious, spammy level. As far as I can tell "We" refers to cybernews.com And again even if cybernews was a PCI-DSS approved scanning vendor it would still have to qualify as an official external scan within the PCI-DSS framework.
- rasengan 7y ago> Not anywhere on the page you linked. Read the page carefully - it specifically states they are an auditor approved org. Quote from page: “Meet penetration testing requirements for PCI DSS and SOC2 Type II compliance certifications with our auditor-approved penetration testing methodology and Security Assessment Report.[1].” Secondly, PayPal works with HackerOne officially [2] and within the CVSS standards as they clearly state on their HackerOne page, which is complying with PCI DSS. [1] https://www.hackerone.com/product/challenge https://www.hackerone.com/product/challenge [2] https://hackerone.com/paypal https://hackerone.com/paypal Edit: Archived incase: http://archive.is/CvZqg http://archive.is/CvZqg http://archive.is/GGDs2 http://archive.is/GGDs2
- teilo 7y agoSorry, but you don't understand what you are looking at. All of HackerOne's information that you cite is about them being PCI-DSS-compliant or having undergone a SOC2 Type 2 audit. Nothing you link to identifies them as a PCI-DSS auditing company. They are not. And the "scans" the PCI-DSS standards refers to are standard pen-test and external vulnerability scans, usually conducted by an accounting company who will certify the scan results. They are for known vulnerabilities, things like the version of Apache you are on, etc. None of the reports sent via HackerOne would qualify as a "scan" under PCI-DSS.
- rasengan 7y ago> All of HackerOne's information that you cite is about them being PCI-DSS-compliant or having undergone a SOC2 Type 2 audit. Nothing you link to identifies them as a PCI-DSS auditing company. They are not. Please read the page again. They specifically say you can achieve compliance certification with HackerOne.
- ailideex 7y agoWe read the page, and even if your claim holds, it is still irrelevant because whatever you quoted is not the same as being a PCI-DSS approved scanning vendor. And even if it was, HackerOne did not perform any scans. HackerOne offering PCI-DSS approved auditor approved challenges gets you nowhere towards the claims you made in your first comment. To review: 1. HackerOne would have to be a PCI DSS Approved Scanning Vendor - they are not AFAICT, neither is the CyberNews research team that did the scan AFAICT. 2. HackerOne would have to have conducted the scan - they did not. The CyberNews research team did. 3. The scan that HackerOne did would have to qualify as a PCI-DSS external scan - which ... do you get the part that HackerOne did not do the scan here or not? And nowhere did the CyberNews research team claim they performed a PCI-DSS external scan. Please at least try to make an argument for your claims
- rasengan 7y ago“SATISFY COMPLIANCE CERTIFICATION REQUIREMENTS Meet pentest requirements for PCI DSS, SOC2 Type II, and HITRUST compliance certifications.” [1] [1] https://www.hackerone.com/product/pentest https://www.hackerone.com/product/pentest
- monadic2 7y ago> I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong. Actually this makes a pretty good case for this regulation being a joke. They clearly aren’t up to the responsibility of being a payment processor and are leaning on the law to sustain their business rather than simply demonstrating aptitude directly.
- moftz 7y agoWhy does the regulatory body get to approve who and what can scan implementations of their security scheme? It seems like the ideal auditor and scanning software, in PCI DSS's eyes, would be the one that just barely checks the boxes for minimum security requirements. Poking too hard at their security scheme would reveal how lackluster it is but they still need someone to poke at it to prove compliance. Being able to ignore anyone or anything that isn't on the approved list seems like willful negligence.
- michaelt 7y ago> Why does the regulatory body get to approve who and what can scan implementations of their security scheme? Because it's a scanner for PCI-DSS compliance, not a scan for security issues. They do not fear that unapproved scanners will be more strict than approved scanners, they fear they will be less strict.
- tedunangst 7y agoBecause when you make the rules you get to make the rules?
- marcus_holmes 7y agoIt works better this way around than the other way around - which would be that PayPal gets to pick who audits them with no oversight. You can imagine how thorough that audit would be, and how many times it would find any problems.
- shkkmo 7y ago
- HoustonRefugee 7y agoFormer QSA here....and that external scanning vendor (one in each quarter) and two required Pen Tests per year had not be HackerOne carrying them out. Automatic conflict of interest. HackerOne has a vested interest in a clean scan and making Paypal look good.
- eecc 7y agoUhm, but weren’t they operating via a bug bounty program? Now they’re supposed to be a registered auditor or whatnot?