3 ms·
> HackerOne states they are a PCI-DSS auditor approved organization Not anywhere on the page you linked. And a "PCI-DSS auditor approved organization" is not a
by ailideex 7y ago
> HackerOne states they are a PCI-DSS auditor approved organization
Not anywhere on the page you linked. And a "PCI-DSS auditor approved organization" is not a "PCI-DSS approved scanning vendor" which if they were you could just quote the certificate number instead of link to HackerOne.
----
EDIT: I guess you are referring to this:
> Meet penetration testing requirements for PCI DSS and SOC2 Type II compliance certifications with our auditor-approved penetration testing methodology and Security Assessment Report.
This in no way is the same as claiming "we are a PCI-DSS auditor approved organization". Which again, would be irrelevant if it was the case.
----
Further, if you read the article, it is clear the "We" does not refer to "HackerOne".
> When we pushed the HackerOne staff for clarification on these issues, they removed points from our Reputation scores, relegating our profiles to a suspicious, spammy level.
As far as I can tell "We" refers to cybernews.com
And again even if cybernews was a PCI-DSS approved scanning vendor it would still have to qualify as an official external scan within the PCI-DSS framework.
- rasengan 7y ago> Not anywhere on the page you linked. Read the page carefully - it specifically states they are an auditor approved org. Quote from page: “Meet penetration testing requirements for PCI DSS and SOC2 Type II compliance certifications with our auditor-approved penetration testing methodology and Security Assessment Report.[1].” Secondly, PayPal works with HackerOne officially [2] and within the CVSS standards as they clearly state on their HackerOne page, which is complying with PCI DSS. [1] https://www.hackerone.com/product/challenge https://www.hackerone.com/product/challenge [2] https://hackerone.com/paypal https://hackerone.com/paypal Edit: Archived incase: http://archive.is/CvZqg http://archive.is/CvZqg http://archive.is/GGDs2 http://archive.is/GGDs2
- ailideex 7y agoWhat is their certificate number?
- hedora 7y ago> If PayPal’s PCI-DSS compliance certification isn’t revoked then PCI-DSS is a farce. This comment chain has convinced me that PCI-DSS is a farce.
- deadmetheny 7y agoPretty much. All it really proves is that an org meets a bare minimum of security standards. As noted elsewhere in the thread, it's used more for marketing and to serve as a "hey look at us we're self-regulating within industry!" than anything else.
- ailideex 7y agoI'm not sure that you being convinced by someone who doesn't even understand that it was not hackerone that found the vulnerabilities says much about PCI-DSS
- singlow 7y agoEven if HackerOne were a company that is licensed to do PCI DSS scans, they were not contracted by PayPal to do it. A PCI DSS scanning company cannot just do independent audits for PCI compliance unless solicited by the target. The auditing process you are referencing is not related at all to reports by unsolicited scanners.
- tomnipotent 7y ago> Read the page carefully Emphasis mine. "...satisfy the requirements for external penetration testing for audited PCI DSS and SOC2 Type II certifications." "Final Report Delivered. Ready for Auditors."