> If PayPal’s PCI-DSS compliance certification isn’t revoked then PCI-DSS is a farce.
This comment chain has convinced me that PCI-DSS is a farce.
I'm not sure that you being convinced by someone who doesn't even understand that it was not hackerone that found the vulnerabilities says much about PCI-DSS
Pretty much. All it really proves is that an org meets a bare minimum of security standards. As noted elsewhere in the thread, it's used more for marketing and to serve as a "hey look at us we're self-regulating within industry!" than anything else.