Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's exactly what I want to know. I definitely do not want to deal with PCI compliance. Sadly Authorize.net doesn't support banks in Canada.


Solutions like CIM only simplify PCI compliance. You're still handling the card info, just not storing it. To completely get away from handling card data you have to send your customer over to another site like PayPal to enter their payment info. A sub-optimal user experience.

That being said, it's less likely for someone to sniff the info as it passes through your server's RAM than if it was stored on disk.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: