Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

PCI-DSS is okay if you put it in an HTTPS iframe. Many sites I've seen use that workaround.


TNope that would violate PCI as well since you are then subject to clickjacking attacks unless you configure the site to only allow framing in from a specific url.


> The Hosted PCI Web Checkout module allows merchants to take credit card information on any page of their website. This includes checkout and my account pages. Hosted PCI uses an “Iframe” that can be easily installed on any website. Our Iframe is secure and is 100% Level 1 PCI Compliant. Our merchant’s websites never see the customer credit card information. That means, our merchants websites are not in scope for PCI Compliance requirements so you don’t have to spend time or tens of thousands on PCI audits yourself!

http://www.hostedpci.com/checkout-express/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: