<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: PCI Compliance Required Soon</title>
	<atom:link href="http://www.365webapplications.com/2010/02/18/pci-compliance-required-soon/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.365webapplications.com/2010/02/18/pci-compliance-required-soon/</link>
	<description>Web Design and Business tips, reviews, and tools</description>
	<lastBuildDate>Thu, 09 Sep 2010 16:19:34 -0400</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Jason</title>
		<link>http://www.365webapplications.com/2010/02/18/pci-compliance-required-soon/comment-page-1/#comment-309</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Fri, 19 Feb 2010 18:23:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.365webapplications.com/?p=769#comment-309</guid>
		<description>Thanks for your comments Mike.  I know where you are coming from and it is going to make things tough on the Mom-and-Pop operations.  Spoke to someone today and he is going to have his site one place and his checkout another, just to comply with PCI.  Not ideal, but it kind of makes sense.  I perceive that PCI compliant checkout services are going to take off if the credit card companies actually crack down on this.  It is just such a wide field, there is no way they are going to be able to check everyone.  I&#039;m sure they&#039;ll be looking for key players to go after and hope that media coverage scares everyone else to take action.  I also agree that nit picky details are not nearly as important as overall best practices.  For instance not storing credit card data at all in your database pretty much eliminates the need for a large portion of the requirements.  If you simply send things to Authorize.net you need to make sure: 1) data is encrypted from the browser to the cart to Auth.net, 2) the system is secure enough that no one messes with the cart code to record this information through that authorization process.</description>
		<content:encoded><![CDATA[<p>Thanks for your comments Mike.  I know where you are coming from and it is going to make things tough on the Mom-and-Pop operations.  Spoke to someone today and he is going to have his site one place and his checkout another, just to comply with PCI.  Not ideal, but it kind of makes sense.  I perceive that PCI compliant checkout services are going to take off if the credit card companies actually crack down on this.  It is just such a wide field, there is no way they are going to be able to check everyone.  I&#8217;m sure they&#8217;ll be looking for key players to go after and hope that media coverage scares everyone else to take action.  I also agree that nit picky details are not nearly as important as overall best practices.  For instance not storing credit card data at all in your database pretty much eliminates the need for a large portion of the requirements.  If you simply send things to Authorize.net you need to make sure: 1) data is encrypted from the browser to the cart to Auth.net, 2) the system is secure enough that no one messes with the cart code to record this information through that authorization process.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://www.365webapplications.com/2010/02/18/pci-compliance-required-soon/comment-page-1/#comment-307</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Thu, 18 Feb 2010 13:24:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.365webapplications.com/?p=769#comment-307</guid>
		<description>PCI compliance is such a joke.  And an annoying one at that.  Some of the PCI Compliance reports we&#039;ve gotten back from clients&#039; banks have things like &quot;Your server is running version 5.2.0 of PHP, and there&#039;s a known bug in that version.  You must upgrade to version 5.2.1&quot;  They don&#039;t bother to check that the bug they mention would be impossible to exploit in the site&#039;s code, but I don&#039;t think they bother to check much of anything...  So for clients in a shared hosting environment, where PHP version upgrades are impossible, you now have a huge problem.  Most Mom-and-Pop eCommerce stores simply can&#039;t afford the hosting requirements or the work involved in getting their sites to match up with these ambiguous requirements.  Okay, rant over.</description>
		<content:encoded><![CDATA[<p>PCI compliance is such a joke.  And an annoying one at that.  Some of the PCI Compliance reports we&#8217;ve gotten back from clients&#8217; banks have things like &#8220;Your server is running version 5.2.0 of PHP, and there&#8217;s a known bug in that version.  You must upgrade to version 5.2.1&#8243;  They don&#8217;t bother to check that the bug they mention would be impossible to exploit in the site&#8217;s code, but I don&#8217;t think they bother to check much of anything&#8230;  So for clients in a shared hosting environment, where PHP version upgrades are impossible, you now have a huge problem.  Most Mom-and-Pop eCommerce stores simply can&#8217;t afford the hosting requirements or the work involved in getting their sites to match up with these ambiguous requirements.  Okay, rant over.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

