Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"Security is everything the should care about in the first place."

profits are all they care about.

Honestly, stuff like this burns me up. Large orgs like this lobbied for crap like PCI compliance standards to 'protect' data, but they don't have to follow their own rules. Seriously, if PCI compliance is mandated for anyone who stores CC info, why the hell isn't citi being shut down for this sort of breach? 'too big to fail'?



Has it been determined that Citi will not face repercussions for this incident? I think part of the reason PCI DSS was created (by the payment processors MasterCard, Visa, Amex, etc) was to allow for more legal leverage against the banks when determining who has to pay damages in scenarios such as this.


No, it hasn't. I'm just jumping the gun in a frothy rage.

Something this egregious should have been caught by PCI compliance checks (if not development) in the first place though.

I doubt the penalty will be anything severe enough - something like "no cc processing and management for citi for 180 days" might make them take this a bit more seriously.


I think PCI is more of a reactive legal tool than it is an effective, proactive way to prevent security breaches. In theory it should catch security vulnerabilities, but I don't know how thorough the compliance checks really are...

Yeah, Citi's greater punishment will likely be in the form of a weakened reputation then it will be in actual damages paid.


They're long, involved and expensive, although I'm not sure how thorough or really preventative they may be - you're right. For companies just getting started, they probably serve more preventative purposes than they do for already established players who were around before the PCI stuff came around.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: