Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed.

Quote from your source:

> If your scan fails, you must schedule a rescan within 30 days to prove that the critical, high-risk or medium-risk vulnerabilities have been patched.

Scan in this sentence refers to "a PCI DSS external scan".

The list of approved vendors that can conduct PCI DSS external scans can be found here: https://www.pcisecuritystandards.org/assessors_and_solutions...

Please find cybernews' certificate number there and quote it for us, I have looked and can't find it.

I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong.

And even if they were an approved scanning vendor, from what little I know about PCI-DSS, these scans are part of larger process - so even if they were an approved scanning vendor the scan failure would still have had to be part of the larger process for this 30 day limit to apply.

I could go on and on about how much I hate PayPal and random other things, but just because I don't like something does not quite justify making false claims about it.



> I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong.

Actually this makes a pretty good case for this regulation being a joke. They clearly aren’t up to the responsibility of being a payment processor and are leaning on the law to sustain their business rather than simply demonstrating aptitude directly.


Why does the regulatory body get to approve who and what can scan implementations of their security scheme? It seems like the ideal auditor and scanning software, in PCI DSS's eyes, would be the one that just barely checks the boxes for minimum security requirements. Poking too hard at their security scheme would reveal how lackluster it is but they still need someone to poke at it to prove compliance. Being able to ignore anyone or anything that isn't on the approved list seems like willful negligence.


> Why does the regulatory body get to approve who and what can scan implementations of their security scheme?

Because it's a scanner for PCI-DSS compliance, not a scan for security issues.

They do not fear that unapproved scanners will be more strict than approved scanners, they fear they will be less strict.


Because when you make the rules you get to make the rules?


It works better this way around than the other way around - which would be that PayPal gets to pick who audits them with no oversight. You can imagine how thorough that audit would be, and how many times it would find any problems.


> Actually this makes a pretty good case for this regulation being a joke.

PCI-DSS is not government regulation, but an industry created and enforced standard. Compliance is not mandated by federal law and only a couple of states have laws that reference it. For example, Nevada requires compliance while Washington doesn't require compliance but does remove liability for breaches for compliant businesses.


I meant it in a looser sense (like “constraint” I guess), but it just reinforces the reputation that PCI-DSS is a checklist you can buy, not meaningful itself.


They "clearly aren't up to the responsibility"? Paypal has one of the larger application security teams in SFBA. You've decided they're not qualified because someone reported a self-XSS and Paypal didn't freak out?

Did you read downthread about the actual "2FA" feature this team "bypassed"?


> Paypal has one of the larger application security teams in SFBA.

It's not the size that matters, but how you use it that counts.


It's not a regulation. It's a contractual obligation between the merchant and the PCI counsel (which is made up by VISA/Mastercard/the backing banks/etc). It was put in place to avoid regulation.


Then perhaps regulation is necessary if this is their level of scrutiny?


Yeah, but in this political climate, we probably can't get regulation passed that isn't written by the companies it regulates.


That will never happen under any circumstance.


regulation: noun. a rule or directive made and maintained by an authority.

Regulations can be self-imposed on an industry, it does not have to be something the government imposes. Calling PCI-DSS a regulation is still accurate despite many people conflating the term "regulation" solely with government action. In this case, the authority creating the regulations is the PCI Security Standards Council who have their power because the big players in the industry give it to them.


Sorry, technically correct is best correct.

Don't look behind the curtain.


PCI-DSS is a joke, just look at all the zero days that have gone on before today, Comodo the CA hacked, DigiNotar to name a few, the recent zero day in Windows hilighted by none other than the NSA back in Jan. The public have ADHD attention spans, so who cares as long as the money keeps rolling in hey? Do you think your politicians, law enforcement, big businesses or Banksters give a toss? Criminals rule the world and its been going on for thousands of years with people believing in things like Religion and Royalty!


HackerOne states they are a PCI-DSS auditor approved organization [1].

[1] https://www.hackerone.com/product/challenge


Sorry, but you don't understand what you are looking at.

All of HackerOne's information that you cite is about them being PCI-DSS-compliant or having undergone a SOC2 Type 2 audit. Nothing you link to identifies them as a PCI-DSS auditing company. They are not.

And the "scans" the PCI-DSS standards refers to are standard pen-test and external vulnerability scans, usually conducted by an accounting company who will certify the scan results. They are for known vulnerabilities, things like the version of Apache you are on, etc. None of the reports sent via HackerOne would qualify as a "scan" under PCI-DSS.


> All of HackerOne's information that you cite is about them being PCI-DSS-compliant or having undergone a SOC2 Type 2 audit. Nothing you link to identifies them as a PCI-DSS auditing company. They are not.

Please read the page again. They specifically say you can achieve compliance certification with HackerOne.


You achieve that compliance by paying HackerOne, as a company, to perform a compliance scan. This does not mean any swinging dick that reports a vulnerability through HackerOne is causing PayPal to fall out of compliance. These scans are planned well in advance and are part of a normal audit cycle. (edit: typo)

On top of that, there's not really any legal issues for being non-compliant, as has been pointed out elsewhere in this thread.


As someone who deals with PCI-DSS compliance in fintech land on a daily basis this thread is showing me there are a lot of people who like to crow on about stuff they don't know a thing about.


You must be new here.


Indeed. However, it's refreshing to see a HN thread that's defending vendor snakeoil instead of assuming all infosec is vendor snakeoil.


We read the page, and even if your claim holds, it is still irrelevant because whatever you quoted is not the same as being a PCI-DSS approved scanning vendor. And even if it was, HackerOne did not perform any scans.

HackerOne offering PCI-DSS approved auditor approved challenges gets you nowhere towards the claims you made in your first comment.

To review:

1. HackerOne would have to be a PCI DSS Approved Scanning Vendor - they are not AFAICT, neither is the CyberNews research team that did the scan AFAICT.

2. HackerOne would have to have conducted the scan - they did not. The CyberNews research team did.

3. The scan that HackerOne did would have to qualify as a PCI-DSS external scan - which ... do you get the part that HackerOne did not do the scan here or not? And nowhere did the CyberNews research team claim they performed a PCI-DSS external scan.

Please at least try to make an argument for your claims


“SATISFY COMPLIANCE CERTIFICATION REQUIREMENTS

Meet pentest requirements for PCI DSS, SOC2 Type II, and HITRUST compliance certifications.” [1]

[1] https://www.hackerone.com/product/pentest


Can you remind me again why hackerone is relevant here? Who claimed where that they performed a PCI DSS external scan that failed?


The page only says that they do external security scans that other companies who do the actual certification recognize as valid scans. They certify no one themselves.

Further, that has absolutely nothing to do with anyone reporting vulnerabilities through HackerOne. That is not a scan by the definition of PCI-DSS, the SOC2 trust services criteria, or any other security framework you care to name.

Just give it up. You're wrong.


> HackerOne states they are a PCI-DSS auditor approved organization

Not anywhere on the page you linked. And a "PCI-DSS auditor approved organization" is not a "PCI-DSS approved scanning vendor" which if they were you could just quote the certificate number instead of link to HackerOne.

----

EDIT: I guess you are referring to this:

> Meet penetration testing requirements for PCI DSS and SOC2 Type II compliance certifications with our auditor-approved penetration testing methodology and Security Assessment Report.

This in no way is the same as claiming "we are a PCI-DSS auditor approved organization". Which again, would be irrelevant if it was the case.

----

Further, if you read the article, it is clear the "We" does not refer to "HackerOne".

> When we pushed the HackerOne staff for clarification on these issues, they removed points from our Reputation scores, relegating our profiles to a suspicious, spammy level.

As far as I can tell "We" refers to cybernews.com

And again even if cybernews was a PCI-DSS approved scanning vendor it would still have to qualify as an official external scan within the PCI-DSS framework.


> Not anywhere on the page you linked.

Read the page carefully - it specifically states they are an auditor approved org.

Quote from page: “Meet penetration testing requirements for PCI DSS and SOC2 Type II compliance certifications with our auditor-approved penetration testing methodology and Security Assessment Report.[1].”

Secondly, PayPal works with HackerOne officially [2] and within the CVSS standards as they clearly state on their HackerOne page, which is complying with PCI DSS.

[1] https://www.hackerone.com/product/challenge

[2] https://hackerone.com/paypal

Edit: Archived incase:

http://archive.is/CvZqg

http://archive.is/GGDs2


Even if HackerOne were a company that is licensed to do PCI DSS scans, they were not contracted by PayPal to do it. A PCI DSS scanning company cannot just do independent audits for PCI compliance unless solicited by the target. The auditing process you are referencing is not related at all to reports by unsolicited scanners.


What is their certificate number?


> If PayPal’s PCI-DSS compliance certification isn’t revoked then PCI-DSS is a farce.

This comment chain has convinced me that PCI-DSS is a farce.


I'm not sure that you being convinced by someone who doesn't even understand that it was not hackerone that found the vulnerabilities says much about PCI-DSS


Pretty much. All it really proves is that an org meets a bare minimum of security standards. As noted elsewhere in the thread, it's used more for marketing and to serve as a "hey look at us we're self-regulating within industry!" than anything else.


> Read the page carefully

Emphasis mine.

"...satisfy the requirements for external penetration testing for audited PCI DSS and SOC2 Type II certifications."

"Final Report Delivered. Ready for Auditors."


Yeah but someone reporting a vulnerability to HackerOne is not the same as HackerOne reporting it. Otherwise you could just spam HackerOne with reports and remove someone’s compliance.


Uhm, but weren’t they operating via a bug bounty program? Now they’re supposed to be a registered auditor or whatnot?


Former QSA here....and that external scanning vendor (one in each quarter) and two required Pen Tests per year had not be HackerOne carrying them out. Automatic conflict of interest. HackerOne has a vested interest in a clean scan and making Paypal look good.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: