Posted - 01/17/2025 : 14:20:49
The 'VikingCloud' emails seemed suspect because 1) PayPal constantly floods us with loan offers and other useless third-party spam, 2) those latest emails link to a secondary domain registered a year ago ('paypal-trustcenter.com'), suggesting PayPal doesn't care enough to integrate, and 3) unlike the painful TLS and SHA-256 overhauls of 2016, the 'VikingCloud' emails state no specific technical requirement or deadlines. We use the current PayPal Checkout v2 and we never store payment card data, so the PayPal PCI compliance page https://www.paypal.com/us/brc/article/pci-dss-compliance-basics mostly states basic requirements (antivirus, firewall, etc.) that any sane merchant would follow. The exceptions are requirements for frequent 'PEN' testing, and formal documentation of all policies, procedures, access logs, systems, and software. Having worked at larger companies that performed those tasks, this seems impractical for those of us not currently in the Fortune 500. Our support reps at webhost ServeLink did confirm that they're PCI compliant, and suggested that we visit that VikingCloud link for a look. However they also seemed to suggest that any third-party PEN testing and ongoing, formal documentation of every security procedure for outside review - at their organization or ours - would be very costly.
Edited by - pauld on 01/17/2025 14:39:51
|