6 ms·
It wouldn't even need to be a poorly written component. There is a good chance they would log the card number along side the transaction in their database.
by jtdowney 13y ago
It wouldn't even need to be a poorly written component. There is a good chance they would log the card number along side the transaction in their database.
- eCa 13y agoUnless they are PCI compliant [1] they really (really) shouldn't, and would deserve any (and all) kind of hurt that's coming to them. [1] https://www.pcisecuritystandards.org/ https://www.pcisecuritystandards.org/