Hacker News new | ask | show | jobs
by videoappeal 5225 days ago
Not sure about this PCI complaint stuff, but perhaps this is why major banking companies jumped from Linode to EC2? Much improvement? Although I must say I have friends working on banking websites in the UK that dont know the whole picture, its not unreasonable to assume that these things are fucked up.
2 comments

From what I know, PCI compliance is firstly, just a guideline. It's not like OSHA, but IANAL.

I also know there are "levels" of PCI compliance. The highest one, which reputable banks should be following, is very strict AFAIK, and includes provisions for controlling who has access to the physical hardware, encryption levels, etc. The fact that a Linode VPS can be 'rooted' via their management software by a sysadmin working for Linode would, from what I can tell, make them unqualified to be used to store banking transaction & customer data, though perhaps I am wrong.

EC2 is now PCI DSS 2.0 compliant which is probably why: http://aws.amazon.com/security/pci-dss-level-1-compliance-fa...