Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
samsama
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
samsama
14y ago
In this case Twitter is the only company that can secure the page containing the iFrame code: Merchant is responsible for: Managing website and servers (if self-hosted), including applicable PCI DSS requirements If website/server host
2.
▲
by
samsama
14y ago
Wrong! Check the Feb PCI clarification update. iFrames don't take anything out of scope because at the end of the day the SSL session shown by the browser is that of the originating site. https://www.pcisecuritystandards.org/pdfs/PCI_DSS