<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <title>Recent Posts in 'recipe 33 "Process Recurring Credit Card Payments" vs. PCI DSS' | Pragmatic Forums</title>
    <link>http://65.74.171.210/forums/43/topics/279</link>
    <language>en-us</language>
    <ttl>60</ttl>
    <description></description>
    <item>
      <title>recipe 33 &amp;quot;Process Recurring Credit Card Payments&amp;quot; vs. PCI DSS posted by Joshua Schairbaum @ Fri, 07 Mar 2008 20:13:08 -0000</title>
      <description>&lt;p&gt;Jochen,&lt;/p&gt;


	&lt;p&gt;Mike&amp;#8217;s correct.  There is nothing in Active Merchant that will make you &lt;span class="caps"&gt;PCI DSS&lt;/span&gt;-compliant, but it doesn&amp;#8217;t open any gaps that aren&amp;#8217;t there anyways.  Disclosure time: I work for &lt;a href="http://www.braintreepaymentsolutions"&gt;Braintree&lt;/a&gt;, so please check on facts, don&amp;#8217;t just take my word for it. :)&lt;/p&gt;


	&lt;p&gt;In reality, no solution gives you &lt;span class="caps"&gt;PCI&lt;/span&gt; compliance out-of-the-box, and be wary of companies who claim that.  We do have a solution that removes almost all of the 230+ &lt;span class="caps"&gt;PCI DSS&lt;/span&gt; controls from the scope of your environment by ensuring that no customer sensitive credit card data touches your environment, reducing your in-scope controls to ~10.  Unlike Paypal, Google Checkout, or Amazon &lt;span class="caps"&gt;FPS&lt;/span&gt;, we do this transparent to your users, so they never see our involvement at all.&lt;/p&gt;


	&lt;p&gt;I don&amp;#8217;t want to hijack this thread at all, but if you&amp;#8217;re interested in talking further, you can find me on the &lt;a href="http://developer.getbraintree.com"&gt;Braintree Developer Community&lt;/a&gt;.&lt;/p&gt;


	&lt;p&gt;For anyone else, a great resource for &lt;span class="caps"&gt;PCI DSS&lt;/span&gt; compliance is the &lt;a href="http://www.pcianswers.com"&gt;&lt;span class="caps"&gt;PCI&lt;/span&gt; Answers Blog&lt;/a&gt;, run by The Aegenis Group.&lt;/p&gt;</description>
      <pubDate>Fri, 07 Mar 2008 20:13:08 -0000</pubDate>
      <guid isPermaLink="false">65.74.171.210:43:279:2405</guid>
      <author>Joshua Schairbaum</author>
      <link>http://65.74.171.210/forums/43/topics/279</link>
    </item>
    <item>
      <title>recipe 33 &amp;quot;Process Recurring Credit Card Payments&amp;quot; vs. PCI DSS posted by Mike Clark @ Mon, 03 Mar 2008 14:47:24 -0000</title>
      <description>&lt;p&gt;Using ActiveMerchant doesn&amp;#8217;t mean you&amp;#8217;re automatically &lt;span class="caps"&gt;PCI DSS&lt;/span&gt; compliant.  ActiveMerchant by itself doesn&amp;#8217;t do anything that would make you not compliant.  However, being &lt;span class="caps"&gt;PCI DSS&lt;/span&gt; compliant is a lot more than just the code.  It stipulates things like access control, monitoring the server room, auditing, documentation, etc.&lt;/p&gt;</description>
      <pubDate>Mon, 03 Mar 2008 14:47:24 -0000</pubDate>
      <guid isPermaLink="false">65.74.171.210:43:279:2364</guid>
      <author>Mike Clark</author>
      <link>http://65.74.171.210/forums/43/topics/279</link>
    </item>
    <item>
      <title>recipe 33 &amp;quot;Process Recurring Credit Card Payments&amp;quot; vs. PCI DSS posted by Jochen Hayek @ Mon, 03 Mar 2008 01:33:09 -0000</title>
      <description>&lt;p&gt;So, on March, 2nd, this was renumbered recipe 35,&lt;br /&gt;and within &amp;#8216;Discussion&amp;#8217; the bullet referring to &amp;#8216;the setup&amp;#8217; just got removed.&lt;br /&gt;Smart approach to getting rid of a problem.&lt;br /&gt;But the question remains&amp;#8212;although it might well be,&lt;br /&gt;that it gets answered now somehow anywhere within the recipe text.&lt;/p&gt;


	&lt;p&gt;Just removing the bullet may solve the issue for somebody,&lt;br /&gt;who reads this recipe w/o knowing its history,&lt;br /&gt;but now, that some doubt arose inside me,&lt;br /&gt;how can I forget it?&lt;/p&gt;</description>
      <pubDate>Mon, 03 Mar 2008 01:33:09 -0000</pubDate>
      <guid isPermaLink="false">65.74.171.210:43:279:2360</guid>
      <author>Jochen Hayek</author>
      <link>http://65.74.171.210/forums/43/topics/279</link>
    </item>
    <item>
      <title>recipe 33 &amp;quot;Process Recurring Credit Card Payments&amp;quot; vs. PCI DSS posted by Mike Clark @ Wed, 27 Feb 2008 19:07:37 -0000</title>
      <description>&lt;p&gt;Good question, and I&amp;#8217;ll ask the author so we can clarify it in the next revisions.  Feel free to file any more errata on the errata page.&lt;/p&gt;


	&lt;p&gt;Thanks!&lt;/p&gt;</description>
      <pubDate>Wed, 27 Feb 2008 19:07:37 -0000</pubDate>
      <guid isPermaLink="false">65.74.171.210:43:279:2345</guid>
      <author>Mike Clark</author>
      <link>http://65.74.171.210/forums/43/topics/279</link>
    </item>
    <item>
      <title>recipe 33 &amp;quot;Process Recurring Credit Card Payments&amp;quot; vs. PCI DSS posted by Jochen Hayek @ Wed, 27 Feb 2008 11:37:11 -0000</title>
      <description>&lt;p&gt;Within the section &amp;#8216;Discussion&amp;#8217; Cody Fauser writes,&lt;br /&gt;that &amp;#8216;all other aspects of the &lt;span class="caps"&gt;PCI DSS&lt;/span&gt; are met by the setup&amp;#8217;.&lt;/p&gt;


	&lt;p&gt;Justing referring to &amp;#8216;the setup&amp;#8217; is a little (pls forgive me) wish-wash.&lt;/p&gt;


	&lt;p&gt;So does that &lt;strong&gt;reliably&lt;/strong&gt; mean,&lt;br /&gt;that active_merchant itself is &amp;#8216;PCI &lt;span class="caps"&gt;DSS&lt;/span&gt;&amp;#8217;-safe?&lt;/p&gt;</description>
      <pubDate>Wed, 27 Feb 2008 11:37:11 -0000</pubDate>
      <guid isPermaLink="false">65.74.171.210:43:279:2341</guid>
      <author>Jochen Hayek</author>
      <link>http://65.74.171.210/forums/43/topics/279</link>
    </item>
  </channel>
</rss>
