Ticketmaster breach 'part of massive bank card slurping campaign'

andy bird

pci is near useless

Nearly all of the PCI mandated 'hoops' and certainly the typical Security Metrix type scans all focus on the server side of the problem.. which is the least likely attack vector.

Why bother attacking the 300ft wall when the application just leaves the door wide open. PCI scans almost never flag unpatched / out of date applications.

