You are currently browsing the Don Forbes weblog archives for November, 2008.

Breaking News

PCI Compliance – Disabling SSL v2

Don @ November 9, 2008 # No Comment Yet

If your ecommerce application is taking credit card numbers and you’re hosting with a reputable host, most likely you’re familiar with becoming PCI Compliant.  Without going into much debate over the policies behind the requierments and motives, one of the things that you must do is disable SSL version 2, which has multiple documented vulnerabilities.  [...]

More on page 39