3 ms·
It's called PCI. Taking payment information in the context of the twitter.com same origin would pull Twitter into PCI compliance scope for Ribbon & possibly im
by ElginEudor 14y ago
It's called PCI. Taking payment information in the context of the twitter.com same origin would pull Twitter into PCI compliance scope for Ribbon & possibly impact Twitters own PCI compliance state. For this to happen there would need to be contracts in place.
- andrewmunsell 14y agoIt's an IFrame, so no credit card info is ever actually on Twitter.com. In fact, the entire Ribbon card interface is served on a different host. Because of that, Twitter doesn't actually have to be PCI compliant-- they never see credit card or payment information.
- samsama 14y agoWrong! Check the Feb PCI clarification update. iFrames don't take anything out of scope because at the end of the day the SSL session shown by the browser is that of the originating site. https://www.pcisecuritystandards.org/pdfs/PCI_DSS_v2_eCommerce_Guidelines.pdf https://www.pcisecuritystandards.org/pdfs/PCI_DSS_v2_eCommer...
- samsama 14y agoIn this case Twitter is the only company that can secure the page containing the iFrame code: Merchant is responsible for: Managing website and servers (if self-hosted), including applicable PCI DSS requirements If website/server hosting is outsourced, applicable PCI DSS requirements for management of third parties (e.g., Requirement 12.8) Having written agreements with any third parties and ensuring that they protect cardholder data on behalf of the merchant, in accordance with PCI DSS Securing the web page(s) containing the iFrame code.