BreachExchange mailing list archives

Re: Best Western Response


From: security curmudgeon <jericho () attrition org>
Date: Tue, 26 Aug 2008 20:52:13 +0000 (UTC)


: The fact is that the PCI DSS program itself is flawed, and provides 
: nothing more than a false sense of security.  When certain "security"  
: companies commoditize "network scanning" to the point that it is an 
: entirely automated effort, the buyer deserves what they are going to 
: get.

And when said scanning vendor is in bed with the PCI Security Standards 
Council as far as ASV certification goes (MC/Visa), the industry deserves 
what they choose to adopt.

_______________________________________________
Dataloss Mailing List (dataloss () attrition org)
http://attrition.org/dataloss

Tenable Network Security offers data leakage and compliance monitoring
solutions for large and small networks. Scan your network and monitor your
traffic to find the data needing protection before it leaks out!
http://www.tenablesecurity.com/products/compliance.shtml


Current thread: