[GRLUG] PCI v1.2 Compliance.

David Pembrook david at pembrook.net
Thu Dec 11 12:43:19 EST 2008


Michael Mol wrote:
> On Thu, Dec 11, 2008 at 12:19 PM, Greg Folkert <greg at gregfolkert.net> wrote:
>   
>> On Wed, 2008-12-10 at 18:29 -0500, Greg Folkert wrote:
>>     
>>> be wrned, my reply is long and could have been orders of magnitude
>>> longer.
>>>
>>> On Wed, 2008-12-10 at 16:05 -0500, Adam Tauno Williams wrote:
>>>       
>>>> On Wed, 2008-12-10 at 15:21 -0500, Greg Folkert wrote:
>>>>         
>>>>> All I can say it *IT SUCKS*.
>>>>>           
>>>> Actually I think PCI is a pretty good standard.  I think 98% of the
>>>> recommendations are solid/good practices.   And it makes a nice club to
>>>> beat good security practices into an organization.
>>>>         
>> [snip lotsa stuff]
>>
>> Any comments from anyone? Or insight? Or contrarian thoughts? Or flames?
>>
>> I'd have really thought many people would feel this... or at least have
>> more comments than from the regular peanut gallery.
>>     
>
> What's the cost comparison to just accepting PayPal?
>
>   
I've got a site I'm working on where the customer wanted to go the 
paypal route and is getting resistance from a small percentage of their 
customers. I prefer the ability to pay and not give the small merchant 
that I've never heard of before my cc info (but who am I).

The end result is the customer doesn't want to loose one sale and if 
that means leaving paypal.. so be it.

Dave


More information about the grlug mailing list