Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Stripe's level one service provider which is independent of the merchants PCI compliance. The merchant is presenting the form for which the user enters their credit card information from within the context (same origin) of their domain: e.g., https://merchant.com/payment... As a result, under the PCI DSS they are obligated to protect that component of the transaction because if they don't a criminal could change it so that the card data doesn't POST to Stripe.com but instead goes to the criminal. Implementing a bit of Javascript and enabling SSL/TLS is far from all that is needed to be PCI compliant as a merchant so long as the payment form itself, whether delivered via an iFrame or a bit of Javascript is hosted within the merchant domain.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: