Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

First rule of financial apps: if you're going to deal with money you should own your servers. The cloud is not an option.

Second rule: Hire a security expert and a thief. The former to keep you safe and the latter to break in before the real ones so the expert can fix the holes.

Btw, I like the service.



I like the service, but AWS (or the cloud in general) is the wrong infrastructure choice for it. AWS is fine for some things, but not for being a payment processor or wallet provider. It's fine if you're just accepting credit card payments through another processor.

They probably won't be able to pass the money transmitter certification on AWS, so presumably they'll migrate eventually.


I hear AWS is certified for credit card processing. Is that not the case?


http://aws.amazon.com/security/pci-dss-level-1-compliance-fa...

Apparently they are now, yes. Last I checked they weren't and were saying their cloud services were inherently uncertifiable, due to the architecture.


Yeah, they changed PCI DSS 2.0 to allow virtual servers, specifically to let Amazon Web Services pass. PCI DSS 1.0 wouldn't work. (level 1 compliance PCI DSS 2.0 from the most trusting/forgiving QSA available, i.e. a pretty fucking low bar)

The PCI firms I know probably would not have passed them.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: