Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

http://aws.amazon.com/security/pci-dss-level-1-compliance-fa...

Apparently they are now, yes. Last I checked they weren't and were saying their cloud services were inherently uncertifiable, due to the architecture.



Yeah, they changed PCI DSS 2.0 to allow virtual servers, specifically to let Amazon Web Services pass. PCI DSS 1.0 wouldn't work. (level 1 compliance PCI DSS 2.0 from the most trusting/forgiving QSA available, i.e. a pretty fucking low bar)

The PCI firms I know probably would not have passed them.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: