Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Even if HackerOne were a company that is licensed to do PCI DSS scans, they were not contracted by PayPal to do it. A PCI DSS scanning company cannot just do independent audits for PCI compliance unless solicited by the target. The auditing process you are referencing is not related at all to reports by unsolicited scanners.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: