3 ms·
Years ago, the announcement came out over IRC that one of our providers demanded to audit our machines for "PCI compliance," and would be in the office the next
by zzgo 2y ago
Years ago, the announcement came out over IRC that one of our providers demanded to audit our machines for "PCI compliance," and would be in the office the next day in our server rooms. I immediately replied that we needed to have someone keep an eye on them at all times. I was dismissed as paranoid, and the "outside auditors" were allowed unsupervised free rein with our machines for the day. These machines contained all of our users' credit card, personal, and travel information.
I was convinced after that incident that protecting users' data just wasn't a priority for startups, and that Mark Zuckerberg's money quote about users being "dumb fscks" for trusting him with their information was the norm in the C-suite and not an aberation.