6 ms·
There is a difference: If the data never touches your server at all, it is impossible for you to inadvertently record it.
by Ralith 14y ago
There is a difference: If the data never touches your server at all, it is impossible for you to inadvertently record it.
- deleted 14y ago[deleted]
- sp332 14y agoIf the iframe that you host is compromised, you have no idea where that info is being recorded. The fact that it doesn't touch your server doesn't ensure that your site isn't leaking numbers.
- Ralith 14y agoCertainly. But it does ensure that access to your server does not entail access to historical numbers.
- flatline3 14y agoUnless the compromise is a long-term one. Part of what PCI attempts to address is limiting legitimate access to servers, as well as preventative measures against compromise. I personally think that Stripe may be within the letter of the law, but not necessarily the spirit.