Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If the iframe that you host is compromised, you have no idea where that info is being recorded. The fact that it doesn't touch your server doesn't ensure that your site isn't leaking numbers.


Certainly. But it does ensure that access to your server does not entail access to historical numbers.


Unless the compromise is a long-term one.

Part of what PCI attempts to address is limiting legitimate access to servers, as well as preventative measures against compromise.

I personally think that Stripe may be within the letter of the law, but not necessarily the spirit.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: