Hacker News new | ask | show | jobs
by tptacek 5301 days ago
There is no good reason for any of these backdoors around PCI, except for the fact that everyone knows it's not going to be feasible to "test"† every website anywhere that does any commerce.

It's probably best not to ask too many questions. It'll only hurt your brain.

(If that's what you want to call PCI assessments)

1 comments

Another thing to keep in mind is that PCI scope and PCI requirements expand with every iteration, so today's backdoor may be gone tomorrow.

PCI compliance is ridiculous enough that it's still worth avoiding though, even if only for the short term.