Comment by solid_fuel 4 hours ago Professional app development requires an understanding of security. 7 comments solid_fuel Reply corndoge 3 hours ago I think the evidence contradicts you at this point orangelimesoda 2 hours ago So you don't need to know anything about credit cards for someone to enter it into an app? I don't get the take (is it bad sarcasm?) devmor 2 hours ago To be fair, for the vast majority of cases, no you don't.It is extremely rare for companies to roll their own payment processing anymore, or even handle PCI scope at all. 3 replies → oenton 1 hour ago To your last question about bucket policies, clearly you just need to scope it down: arn:aws:sts::*:assumed-role/trustme*/*(indeed that first wildcard means any account)
corndoge 3 hours ago I think the evidence contradicts you at this point orangelimesoda 2 hours ago So you don't need to know anything about credit cards for someone to enter it into an app? I don't get the take (is it bad sarcasm?) devmor 2 hours ago To be fair, for the vast majority of cases, no you don't.It is extremely rare for companies to roll their own payment processing anymore, or even handle PCI scope at all. 3 replies → oenton 1 hour ago To your last question about bucket policies, clearly you just need to scope it down: arn:aws:sts::*:assumed-role/trustme*/*(indeed that first wildcard means any account)
orangelimesoda 2 hours ago So you don't need to know anything about credit cards for someone to enter it into an app? I don't get the take (is it bad sarcasm?) devmor 2 hours ago To be fair, for the vast majority of cases, no you don't.It is extremely rare for companies to roll their own payment processing anymore, or even handle PCI scope at all. 3 replies → oenton 1 hour ago To your last question about bucket policies, clearly you just need to scope it down: arn:aws:sts::*:assumed-role/trustme*/*(indeed that first wildcard means any account)
devmor 2 hours ago To be fair, for the vast majority of cases, no you don't.It is extremely rare for companies to roll their own payment processing anymore, or even handle PCI scope at all. 3 replies →
oenton 1 hour ago To your last question about bucket policies, clearly you just need to scope it down: arn:aws:sts::*:assumed-role/trustme*/*(indeed that first wildcard means any account)
I think the evidence contradicts you at this point
So you don't need to know anything about credit cards for someone to enter it into an app? I don't get the take (is it bad sarcasm?)
To be fair, for the vast majority of cases, no you don't.
It is extremely rare for companies to roll their own payment processing anymore, or even handle PCI scope at all.
3 replies →
To your last question about bucket policies, clearly you just need to scope it down: arn:aws:sts::*:assumed-role/trustme*/*
(indeed that first wildcard means any account)