[rescue] FC-AL drives on sale at geeks.com

Nadine Miller velociraptor at gmail.com
Sun Jan 13 14:53:17 CST 2008


Patrick Giagnocavo wrote:
> On Jan 8, 2008, at 2:35 AM, Jonathan C. Patschke wrote:
> 
>> On Mon, 7 Jan 2008, Dan Duncan wrote:
>>
>>> http://consumerist.com/341408/geekscom-website-hacked-customer- 
>>> data-stolen
>> Interesting that the verification numbers were stored there.  It's my
>> understanding that the merchant agreements (and the card issuers
>> themselves) forbid retaining the verification number.
>>
>> -- 
> 
> That is correct, though Visa/MC don't seem to really care too much as  
> long as what happens doesn't hurt their brand.

Having dealt with two CCI audits at two recent past places of work, 
their audits are less than reassuring.  Essentially, if the organization 
is willing to lie and manufacture data for their auditors it can pass. 
The auditors do no actual confirmation of the information presented, not 
even to the point of shoulder-surfing to see data being generated in 
real time.

=Nadine=



More information about the rescue mailing list