Hacker News new | ask | show | jobs
by vox_mollis 3649 days ago
Indeed. Their PCI-DSS compliance scanning service is completely useless. Service version fingerprinting only, regardless of binary patch level or actual vulns.

Yet somehow, the PCI SSC accepts their scan results as actionable for Level 1-3 compliance.

1 comments

PCI verification is a rubber stamp all the way through, is how.