4 ms·
You achieve that compliance by paying HackerOne, as a company, to perform a compliance scan. This does not mean any swinging dick that reports a vulnerability t
by deadmetheny 7y ago
You achieve that compliance by paying HackerOne, as a company, to perform a compliance scan. This does not mean any swinging dick that reports a vulnerability through HackerOne is causing PayPal to fall out of compliance. These scans are planned well in advance and are part of a normal audit cycle. (edit: typo)
On top of that, there's not really any legal issues for being non-compliant, as has been pointed out elsewhere in this thread.
- whatsmyusername 7y agoAs someone who deals with PCI-DSS compliance in fintech land on a daily basis this thread is showing me there are a lot of people who like to crow on about stuff they don't know a thing about.
- deadmetheny 7y agoIndeed. However, it's refreshing to see a HN thread that's defending vendor snakeoil instead of assuming all infosec is vendor snakeoil.
- deleted 7y ago[deleted]
- tptacek 7y agoYou must be new here.