4 ms·
Everyone is entitled to their value scheme. Unfortunately, the regulatory requirements here have nothing to do with data security; they are imposed to nominally
by thinkcomp 15y ago
Everyone is entitled to their value scheme. Unfortunately, the regulatory requirements here have nothing to do with data security; they are imposed to nominally insure the security of funds. I think it is possible that where you see a pure regulatory failure, I see a technological failure that is being exacerbated by regulation.
- tptacek 15y agoI'd be interested in hearing how regulation is impeding data security. From my vantage point, we have the opposite problem; for instance, credit card processing as an industry has opted for self-regulation, and the resulting PCI standard is ineffective and provides cover for a cottage industry of superficial and inadequate testing. Just to set the stage here, though: you're someone who wants it to be cheaper and easier to start payment processors, and I'm someone who gets paid to find vulnerabilities in complicated applications. Before you write a lot of paragraphs, know that I'm going to drive into specifics, and that I'm decently familiar with data security issues at transaction processors.
- deleted 15y ago[deleted]