logoalt Hacker News

vntoktoday at 2:54 PM1 replyview on HN

Well you were the one talking about "If I get a card number, type it into my POS system, collect money".

A PCI DSS violation is indistinguisable from fraud. If you collect random credit card numbers and then transact on them, you'll be harshly punished. Actually providing a service on the side of the fraud does not make the fraud disappear.

The proposed fix to make contracts established over inbound calls void is useful as a guide for the public to clearly know their rights. And if a company still chooses to collect a payment over the phone, now that's not only a PCI DSS violation but also a theft because money changed hands from an individual to a company without a valid contract.


Replies

wpietritoday at 3:23 PM

I was talking about it in the context of a conversation with someone else, one easily available to you. It is frustrating to have someone not only give an irrelevant reply but then double down on the misunderstanding.