Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Good answer. The problem is the mismatch between the business that they think they're in and the business that they are becoming.

However I am not finding anything about "you may not store passwords in plain text or using reversible encryption" in that PCIDSS wikipedia link. If it is part of the standard (as it should be) then it deserves to be in the wikipedia article.



I may be confusing it with other standards that we had to ensure we were compliant with on a project a couple of years ago.

Even if it isn't in PCIDSS, not storing passwords securely is certainly not industry practice for any company that operates as a bank in any of its parts.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: