TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Someone just lost 324k payment records, complete with CVVs

77 点作者 just_observing超过 8 年前

3 条评论

just_observing超过 8 年前
&quot;Let&#x27;s talk about that CVV for a moment. ... PCI DSS is very clear about how the CVV (or CVV2 as it is these days) should be stored ... It shouldn&#x27;t be stored and that&#x27;s what makes this breach such a big issue. Violation of PCI DSS guidelines can lead to pretty serious fines and even loss of merchant facilities; the card providers take this very seriously.<p>It checked out - this is the CVV.&quot;
评论 #12490654 未加载
评论 #12495679 未加载
admiralhack_超过 8 年前
The author doesn&#x27;t explicitly mention it, but the CVVs were saved as a part of debug logging. That mistake should serve as a warning to others implementing PCI DSS systems.
评论 #12520413 未加载
评论 #12493291 未加载
oneloop超过 8 年前
Oh man this Troy guy is the hero we need, fighting the good fight.