<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Why Open Source Drives PCI Nuts</title>
	<atom:link href="http://storefrontbacktalk.com/securityfraud/why-open-source-drives-pci-nuts/feed/" rel="self" type="application/rss+xml" />
	<link>http://storefrontbacktalk.com/securityfraud/why-open-source-drives-pci-nuts/</link>
	<description>Techniques, Tools and Tirades about Retail Technology and E-Commerce</description>
	<lastBuildDate>Wed, 08 Feb 2012 16:02:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Greg McGraw</title>
		<link>http://storefrontbacktalk.com/securityfraud/why-open-source-drives-pci-nuts/comment-page-1/#comment-74594</link>
		<dc:creator>Greg McGraw</dc:creator>
		<pubDate>Thu, 17 Jun 2010 13:25:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=5517#comment-74594</guid>
		<description>From a customization standpoint, open source software is great. But, paractically speaking, there is no way to audit the software for PA-DSS for that very same reason.  We continue to preach &#039;outsourcing&#039; payment acceptance to our open source merchants exclusively to one or more certified 3rd parties which effectively takes the software out of the scope of PCI and the categorization as a payment application. Level 4 merchants should research hosted payment pages, alternative payments, etc. and not rely solely on scans to claim that they are PCI compliant or rely on the shopping cart maker to PA DSS their software, which is clearly not in their basket of expertise.</description>
		<content:encoded><![CDATA[<p>From a customization standpoint, open source software is great. But, paractically speaking, there is no way to audit the software for PA-DSS for that very same reason.  We continue to preach &#8216;outsourcing&#8217; payment acceptance to our open source merchants exclusively to one or more certified 3rd parties which effectively takes the software out of the scope of PCI and the categorization as a payment application. Level 4 merchants should research hosted payment pages, alternative payments, etc. and not rely solely on scans to claim that they are PCI compliant or rely on the shopping cart maker to PA DSS their software, which is clearly not in their basket of expertise.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shiva</title>
		<link>http://storefrontbacktalk.com/securityfraud/why-open-source-drives-pci-nuts/comment-page-1/#comment-73834</link>
		<dc:creator>Shiva</dc:creator>
		<pubDate>Fri, 11 Jun 2010 08:42:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=5517#comment-73834</guid>
		<description>Reminds me on a similar question on custom vendor ( again it was a customized oscommerce solution ). The vendor was asked on the PCI compliance and it was well put in that the bridge may not be established between PCI and software untill the software was finalized ( up and ready for the market ). I think that is the case with most open source software... after Os software is the clay and it can moulded anyway for that matter :).</description>
		<content:encoded><![CDATA[<p>Reminds me on a similar question on custom vendor ( again it was a customized oscommerce solution ). The vendor was asked on the PCI compliance and it was well put in that the bridge may not be established between PCI and software untill the software was finalized ( up and ready for the market ). I think that is the case with most open source software&#8230; after Os software is the clay and it can moulded anyway for that matter :).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Evan Schuman</title>
		<link>http://storefrontbacktalk.com/securityfraud/why-open-source-drives-pci-nuts/comment-page-1/#comment-73808</link>
		<dc:creator>Evan Schuman</dc:creator>
		<pubDate>Fri, 11 Jun 2010 01:58:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=5517#comment-73808</guid>
		<description>That&#039;s the danger. With any kind of modification, the app vendor is no longer responsible and the duty falls directly on the merchant, just as it had been a fully homegrown app.</description>
		<content:encoded><![CDATA[<p>That&#8217;s the danger. With any kind of modification, the app vendor is no longer responsible and the duty falls directly on the merchant, just as it had been a fully homegrown app.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Juan David</title>
		<link>http://storefrontbacktalk.com/securityfraud/why-open-source-drives-pci-nuts/comment-page-1/#comment-73805</link>
		<dc:creator>Juan David</dc:creator>
		<pubDate>Fri, 11 Jun 2010 01:50:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=5517#comment-73805</guid>
		<description>Hi everyone, I think that if an open source package is modified in any way, that software must be considered, automatically, a custom made application, and must comply with all requirement 6.</description>
		<content:encoded><![CDATA[<p>Hi everyone, I think that if an open source package is modified in any way, that software must be considered, automatically, a custom made application, and must comply with all requirement 6.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marc</title>
		<link>http://storefrontbacktalk.com/securityfraud/why-open-source-drives-pci-nuts/comment-page-1/#comment-73727</link>
		<dc:creator>Marc</dc:creator>
		<pubDate>Thu, 10 Jun 2010 12:04:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=5517#comment-73727</guid>
		<description>Open Source and PCI can match well together: just to mention upcoming Magento PA-DSS compliance or CRESecure solution.</description>
		<content:encoded><![CDATA[<p>Open Source and PCI can match well together: just to mention upcoming Magento PA-DSS compliance or CRESecure solution.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

