3 ms·
The PCI DSS does differentiate between handling encrypted data and handling unencrypted data -- some requirements are only in scope if handling unencrypted data
by dan_manges 15y ago
The PCI DSS does differentiate between handling encrypted data and handling unencrypted data -- some requirements are only in scope if handling unencrypted data. It's important to note that Transparent Redirect doesn't remove the need for a merchant to become PCI compliant, it only reduces the scope of what's necessary to achieve compliance.
It's true that if your form is hacked it could be modified to send credit card details to an attacker. But that's also true even if you're redirecting the user to a third party page like Paypal to complete the payment. If hacked, somebody could change the Paypal button to redirect to a malicious page.
- boucher 15y agoAbsolutely. Any page in the process served without SSL introduces a vulnerability. None of that is explicitly within the scope of PCI.