[Dataloss] Best Western Response

security curmudgeon jericho at attrition.org
Tue Aug 26 20:52:13 UTC 2008


: The fact is that the PCI DSS program itself is flawed, and provides 
: nothing more than a false sense of security.  When certain "security"  
: companies commoditize "network scanning" to the point that it is an 
: entirely automated effort, the buyer deserves what they are going to 
: get.

And when said scanning vendor is in bed with the PCI Security Standards 
Council as far as ASV certification goes (MC/Visa), the industry deserves 
what they choose to adopt.



More information about the Dataloss mailing list