Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Group drafts rules to nix credit-card storage
Robert Lemos, SecurityFocus 2007-11-19

The organization responsible for technical and best-practice standards in the payment industry plans to require the makers of merchant software to certify that their programs do not store sensitive data.

Comments Mode:
Group drafts rules to nix credit-card storage 2007-11-20
Rob Shein
The quote from Gordon Rapkin makes me want to drag a cheese grater across my face to make the bad voices stop. It amazes me that there are still people out there...a CEO of a data protection firm, no less, in this case...who think that it's a valid complaint that a single action won't stop all fraud. True enough; the PA-DSS stops a single type of problem that's related to fraud...but it's an enormous one. If the fact that it's only one hole in the dike (and there is more than one hole) makes it unworthy as a solution, then we might as well all go back to handling cash based on the gold standard, because there isn't a single point from which all fraud originates, and there never has been.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11496/34910#34910







 

Privacy Statement
Copyright 2009, SecurityFocus