Hacker News new | past | comments | ask | show | jobs | submit login

This isn't a set of security best practices. Many are simply required by PCI-DSS, along with a whole bunch of other things if you're doing card payments.

Some of them do offer security benefits (e.g. tokenization) but are often considered more because they reduce cardholder data within your network, which can make things a lot cheaper. A rare example of economic and security factors aligning!




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: