Re: [WebDNA] OT: Issue with some clouds

This WebDNA talk-list message is from

2009


It keeps the original formatting.
numero = 103265
interpreted = N
texte = I'm still a little fuzzy on the PCI compliance thing... (I haven't done a CC site since the new regulations went into effect). If a small merchant has a storefront site, goes through a gateway (e.g. Authorize.net), does not store any card info, but only passes it through the site to the gateway, and receives confirmation back, does that merchant have to do anything more than have an SSL? Bob Minor wrote: > Not sure how many of you were looking to use a cloud for your solutions > > News from Slashdot > > Amazon Confirms EC2/S3 Not PCI Level 1 Compliant > > "After months of digging though speculation and polar opposite > opinions from PCIexperts, I finally sent a direct request to Amazon's > AWS sales team asking if they are in fact PCI compliant and will > provide documentation attesting that they are as is required by PCI > guidlines. I fully expecting them to dodge the question and refer me > to a QSA, but to my relief, they replied with a refreshingly honest > and absolute confirmation that it is currently impossible to meet PCI > level 1 compliance using AWS services for card data storage. They also > very strong suggest that cardnumbers never be stored on EC2 or S3 as > those services are inherently noncompliant. For now at least, the > official verdict is if you need to process credit cards, the Amazon > cloud platform is off the table. > > I vaguely recall some folks recently debating their use, if not then > pardon the intrusion Associated Messages, from the most recent to the oldest:

    
  1. Re: [WebDNA] OT: Issue with some clouds (Bob Minor 2009)
  2. Re: [WebDNA] OT: Issue with some clouds ("Dennis J. Bonsall, Jr." 2009)
  3. Re: [WebDNA] OT: Issue with some clouds (Matthew Bohne 2009)
I'm still a little fuzzy on the PCI compliance thing... (I haven't done a CC site since the new regulations went into effect). If a small merchant has a storefront site, goes through a gateway (e.g. Authorize.net), does not store any card info, but only passes it through the site to the gateway, and receives confirmation back, does that merchant have to do anything more than have an SSL? Bob Minor wrote: > Not sure how many of you were looking to use a cloud for your solutions > > News from Slashdot > > Amazon Confirms EC2/S3 Not PCI Level 1 Compliant > > "After months of digging though speculation and polar opposite > opinions from PCIexperts, I finally sent a direct request to Amazon's > AWS sales team asking if they are in fact PCI compliant and will > provide documentation attesting that they are as is required by PCI > guidlines. I fully expecting them to dodge the question and refer me > to a QSA, but to my relief, they replied with a refreshingly honest > and absolute confirmation that it is currently impossible to meet PCI > level 1 compliance using AWS services for card data storage. They also > very strong suggest that cardnumbers never be stored on EC2 or S3 as > those services are inherently noncompliant. For now at least, the > official verdict is if you need to process credit cards, the Amazon > cloud platform is off the table. > > I vaguely recall some folks recently debating their use, if not then > pardon the intrusion Matthew Bohne

DOWNLOAD WEBDNA NOW!

Top Articles:

Talk List

The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...

Related Readings:

convertchars and e-mail (1998) & not allowed in db by definition? (1999) RE: Sum of Quantities (1997) PROBLEM (1997) Greeting Card System (2000) Intermitent problem using [referrer] (1997) Pithy questions on webcommerce & siteedit (1997) Using Applescript to process WebCatalog functions (1998) trouble updating records in database (1998) Here we go again... (2006) [WebDNA] Website almost dead? (2016) Additional license? (2006) WebCatalog2 Feature Feedback (1996) WebDNA Trouble... (1999) OSX Webcatalog Install (2001) ShowNext example for GeneralStore (1997) A quickie question (1997) What am I missing (1997) well sort of - database design (2003) Size images (2002)