Hacker News new | ask | show | jobs
by 16s 4614 days ago
The way I read the standard, the string 'soccer1' is a valid/compliant PCI password. At least it for PCI-DSS v2.

8.5.10 Require a minimum password length of at least seven characters.

8.5.11 Use passwords containing both numeric and alphabetic characters.

In fact, the string 'password1' exceeds the requirements.