NHacker Next
  • new
  • past
  • show
  • ask
  • show
  • jobs
  • submit
PCI DSS DMARC Requirement: What Section 5.4.1 Requires (dmarcguard.io)
john_strinlai 7 days ago [-]
this article takes more time to read than dmarc takes to implement
tptacek 6 days ago [-]
Kind of a weird post, since it acknowledges in the first 1/3rd that you don't need DMARC for PCI compliance.
CodesInChaos 6 days ago [-]
> The best practice is a policy banning PAN over email, instant messaging, SMS, and chat entirely.

Sounds silly to me. A PAN should never even touch an employee's computer.

dogma1138 6 days ago [-]
There are cases for card not present transactions, fraud and complex refunds but generally yes.
yonatan8070 6 days ago [-]
Took me too long to realize this has nothing to do with the Peripheral Component Interconnect or Direct Memory Access
fragmede 6 days ago [-]
two words: compensating control.

(But also setup dmarc)

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
Rendered at 03:33:26 GMT+0000 (Coordinated Universal Time) with Vercel.