Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

PCI-DSS does not have Bug Bounty requirements. That's referring to ASV scans which have to be run quarterly by a specific list of vendors and then there's a dispute/remediation process.

Their response is dogshit but not for this reason.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: