Hacker News new | ask | show | jobs
by wrs 5816 days ago
These threads always seem to need the following debunking: The PCI compliance requirements are not reduced just because your servers don't store CC numbers. If they even see the numbers, the requirements are essentially the same. To avoid PCI hassles while maintaining control over the UI, you need to use something like Braintree's "transparent redirect".