Hacker News new | ask | show | jobs
by StavrosK 4063 days ago
Maybe I'm wrong, but the few times I've had to fix PCI-scanned sites for compliance, the feedback was just whatever an external automated tool could find, which was almost nothing, and when you fixed the few warnings in the otherwise abysmal codebase, you got the approval.