Hacker News new | ask | show | jobs
by dbg31415 3568 days ago
The other response was good, but yeah to be clear you don't want to go blocking your customer service IPs... that's just going to impede sales / returns / their ability to do their job.

You want to encourage your company as a whole, development and legal and everyone else, to take part in regular 3rd party audits and training around PCI Best Practices.

My point at the start of this was just that it doesn't do any good to dismiss this as "scammy" or think that one team can do this by themselves.

There's no "dev solution" here -- it's gotta be a company solution. (=