Reply to post:

Vision Direct 'fesses up to hack that exposed customer names, payment cards

Chris King

"still supports TLS1.0"

If that server is handling card data (and not handing off to a payment gateway), it's not compliant under PCI DSS 3.2.1 - SSL 3.0 and "Early TLS" (1.0) got the chop in June.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon