|
|
|
|
|
by neurotixz
4223 days ago
|
|
Very interesting, and I would definitely see a use. Just a few comments: - How does this fit into the PCI picture, only thing I have seen on the site is a 2 line faq entry. Not enough to help on scoping or identifying requirements that would apply. - How secure is it, and how are security notifications done? Keeping the software secure and up to date should be considered as critical. I would add a section on the site pertaining to security and addressing vulnerabilities. I did not see on the site information about security updates/patches. They might be on GitHub but it is way to deep to be useful to most people. This kind of software is a perfect example of a high-value target for intrusion, I am a bit worried for the security of the information it contains, especially for smaller startups with limited resources, as well as zombie installations that can be forgotten in a corner with personal information or cards information inside. Not saying it's a bad idea BTW, just a few concerns as a security analyst. |
|
Regarding PCI, it's up to you. You can run it inside your PCI environment or delegate it to your payment provider (via CC tokenization).