Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Even if the cookies would be properly encrypted, it still violates PCI DSS mandatory requirements - you aren't supposed to store or send a full credit card number unless necessary for an actual transaction.

They could do without a (full) CC number there. Ergo, it's a violation.

It's simple defense in depth, and does reduce the risks - say, if the encryption you thought was secure really isn't, etc.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: