<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: PCI Threatens Small Business and Web Hosting Companies</title>
	<atom:link href="http://philosecurity.org/2010/02/08/pci-stresses-small-business-and-web-hosting-companies/feed" rel="self" type="application/rss+xml" />
	<link>http://philosecurity.org/2010/02/08/pci-stresses-small-business-and-web-hosting-companies</link>
	<description></description>
	<lastBuildDate>Tue, 08 Nov 2011 22:48:18 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Jim</title>
		<link>http://philosecurity.org/2010/02/08/pci-stresses-small-business-and-web-hosting-companies/comment-page-1#comment-5802</link>
		<dc:creator>Jim</dc:creator>
		<pubDate>Tue, 23 Feb 2010 03:52:04 +0000</pubDate>
		<guid isPermaLink="false">http://philosecurity.org/?p=3084#comment-5802</guid>
		<description>I agree with your central point that small businesses can&#039;t afford the time or the effort to ensure that they&#039;re PCI compliant. However there is another alternative to going out of business: the small business can just outsource the payment processing bit to one of the established processors. 

If they&#039;re not holding sensitive data, then they don&#039;t need to be PCI compliant as I understand it. For a fee of between 2% and 4% they can make all the headaches go away. The data is held by larger organizations more equipped to handle it, and with the resources to look after it (or so they would have us believe). Everyone wins for the sake of a small percentage increase in price to the consumer  ...</description>
		<content:encoded><![CDATA[<p>I agree with your central point that small businesses can&#8217;t afford the time or the effort to ensure that they&#8217;re PCI compliant. However there is another alternative to going out of business: the small business can just outsource the payment processing bit to one of the established processors. </p>
<p>If they&#8217;re not holding sensitive data, then they don&#8217;t need to be PCI compliant as I understand it. For a fee of between 2% and 4% they can make all the headaches go away. The data is held by larger organizations more equipped to handle it, and with the resources to look after it (or so they would have us believe). Everyone wins for the sake of a small percentage increase in price to the consumer  &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LonerVamp</title>
		<link>http://philosecurity.org/2010/02/08/pci-stresses-small-business-and-web-hosting-companies/comment-page-1#comment-5781</link>
		<dc:creator>LonerVamp</dc:creator>
		<pubDate>Thu, 11 Feb 2010 14:49:18 +0000</pubDate>
		<guid isPermaLink="false">http://philosecurity.org/?p=3084#comment-5781</guid>
		<description>As a footnote, I&#039;m not the &quot;Mike&quot; in the story, despite dropping the &quot;Des Moines&quot; in there (which is where I live!). :)</description>
		<content:encoded><![CDATA[<p>As a footnote, I&#8217;m not the &#8220;Mike&#8221; in the story, despite dropping the &#8220;Des Moines&#8221; in there (which is where I live!). <img src='http://philosecurity.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LonerVamp</title>
		<link>http://philosecurity.org/2010/02/08/pci-stresses-small-business-and-web-hosting-companies/comment-page-1#comment-5773</link>
		<dc:creator>LonerVamp</dc:creator>
		<pubDate>Wed, 10 Feb 2010 15:29:21 +0000</pubDate>
		<guid isPermaLink="false">http://philosecurity.org/?p=3084#comment-5773</guid>
		<description>I&#039;m surprised you don&#039;t have more comments, but then again I think your interview points out some of the ditry little secrets of PCI. Most importantly that it is a difficult and painful and costly standard to step up to. As if there wasn&#039;t already a costly technical barrier to many SMBs or all the costs of operating in a technological world!

That&#039;s not to say small businesses like a web hosting provider shouldn&#039;t be expected to invest in security (or PCI), but I certainly do understand their pain.

It does make you wonder, though. Do you get any real security benefit by *forcing* security standards? If a child doesn&#039;t want to clean his room, but you make him do it or take away the X-box, do you think you&#039;ll get a good job out of him? You&#039;ll get just enough to avoid the punishment, even so far as just shoving everything under the bed or into the closet en masse!</description>
		<content:encoded><![CDATA[<p>I&#8217;m surprised you don&#8217;t have more comments, but then again I think your interview points out some of the ditry little secrets of PCI. Most importantly that it is a difficult and painful and costly standard to step up to. As if there wasn&#8217;t already a costly technical barrier to many SMBs or all the costs of operating in a technological world!</p>
<p>That&#8217;s not to say small businesses like a web hosting provider shouldn&#8217;t be expected to invest in security (or PCI), but I certainly do understand their pain.</p>
<p>It does make you wonder, though. Do you get any real security benefit by *forcing* security standards? If a child doesn&#8217;t want to clean his room, but you make him do it or take away the X-box, do you think you&#8217;ll get a good job out of him? You&#8217;ll get just enough to avoid the punishment, even so far as just shoving everything under the bed or into the closet en masse!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bbot</title>
		<link>http://philosecurity.org/2010/02/08/pci-stresses-small-business-and-web-hosting-companies/comment-page-1#comment-5766</link>
		<dc:creator>bbot</dc:creator>
		<pubDate>Mon, 08 Feb 2010 22:22:00 +0000</pubDate>
		<guid isPermaLink="false">http://philosecurity.org/?p=3084#comment-5766</guid>
		<description>Perhaps add a paragraph at the beginning explaining what PCI/DSS is, for those too lazy to follow a link then decipher corporatese.

Otherwise, a fine interview. I look forward to seeing more of them.</description>
		<content:encoded><![CDATA[<p>Perhaps add a paragraph at the beginning explaining what PCI/DSS is, for those too lazy to follow a link then decipher corporatese.</p>
<p>Otherwise, a fine interview. I look forward to seeing more of them.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

