Artwork

Innehåll tillhandahållet av THE COMMERCE HERO SHOW and Kalen Jordan. Allt poddinnehåll inklusive avsnitt, grafik och podcastbeskrivningar laddas upp och tillhandahålls direkt av THE COMMERCE HERO SHOW and Kalen Jordan eller deras podcastplattformspartner. Om du tror att någon använder ditt upphovsrättsskyddade verk utan din tillåtelse kan du följa processen som beskrivs här https://sv.player.fm/legal.
Player FM - Podcast-app
Gå offline med appen Player FM !

Magento 1 EOL and PCI Compliance

3:27
 
Dela
 

Manage episode 242544308 series 1435359
Innehåll tillhandahållet av THE COMMERCE HERO SHOW and Kalen Jordan. Allt poddinnehåll inklusive avsnitt, grafik och podcastbeskrivningar laddas upp och tillhandahålls direkt av THE COMMERCE HERO SHOW and Kalen Jordan eller deras podcastplattformspartner. Om du tror att någon använder ditt upphovsrättsskyddade verk utan din tillåtelse kan du följa processen som beskrivs här https://sv.player.fm/legal.
A common question I see related to Magento 1 reaching End of Life is whether a store that stays on M1 will automatically fail PCI compliance. I’m not a PCI expert, and don't take any of this as official guidance, but generally the answer is, it depends. Security issues within the Magento world are unacceptably high. The credit agencies that officially look at PCI compliance are undoubtedly aware of that problem. At the end of the day, though, with hundreds of thousands of stores on M1, if it’s passed EOL but the rate of hacks is acceptable, I believe they will continue to accept that business. One of the simplest ways to approach this is to keep the software out of scope for PCI compliance by handling payment processing through a third party. (Honestly you should probably be doing that anyway in most cases, even if you are on an officially supported version of Magento.) Even in-scope software that’s past EOL can be supported. Other parties such as Nexcess can provide official support for M1. To stay on the conservative side, you might not want to be on a software that’s past EOL. But the idea that if you are on M1, you are automatically out of PCI compliance isn’t necessarily true. It’s more nuanced than that. We’ll have to see what happens as we hit EOL. Questions will be answered and new precedents will be set.
  continue reading

41 episoder

Artwork
iconDela
 
Manage episode 242544308 series 1435359
Innehåll tillhandahållet av THE COMMERCE HERO SHOW and Kalen Jordan. Allt poddinnehåll inklusive avsnitt, grafik och podcastbeskrivningar laddas upp och tillhandahålls direkt av THE COMMERCE HERO SHOW and Kalen Jordan eller deras podcastplattformspartner. Om du tror att någon använder ditt upphovsrättsskyddade verk utan din tillåtelse kan du följa processen som beskrivs här https://sv.player.fm/legal.
A common question I see related to Magento 1 reaching End of Life is whether a store that stays on M1 will automatically fail PCI compliance. I’m not a PCI expert, and don't take any of this as official guidance, but generally the answer is, it depends. Security issues within the Magento world are unacceptably high. The credit agencies that officially look at PCI compliance are undoubtedly aware of that problem. At the end of the day, though, with hundreds of thousands of stores on M1, if it’s passed EOL but the rate of hacks is acceptable, I believe they will continue to accept that business. One of the simplest ways to approach this is to keep the software out of scope for PCI compliance by handling payment processing through a third party. (Honestly you should probably be doing that anyway in most cases, even if you are on an officially supported version of Magento.) Even in-scope software that’s past EOL can be supported. Other parties such as Nexcess can provide official support for M1. To stay on the conservative side, you might not want to be on a software that’s past EOL. But the idea that if you are on M1, you are automatically out of PCI compliance isn’t necessarily true. It’s more nuanced than that. We’ll have to see what happens as we hit EOL. Questions will be answered and new precedents will be set.
  continue reading

41 episoder

Alla avsnitt

×
 
Loading …

Välkommen till Player FM

Player FM scannar webben för högkvalitativa podcasts för dig att njuta av nu direkt. Den är den bästa podcast-appen och den fungerar med Android, Iphone och webben. Bli medlem för att synka prenumerationer mellan enheter.

 

Snabbguide