Vaulting Credit Cards
blog.spreedly.com
blog.spreedly.com
The power of this allows companies to use merchant services available to them without having to worry about PCI compliance!
That way, you wouldn't rely on any third-party provider, such as spreedly.com.
Namely - you still have the liability, you still have the maintenance and upkeep of the system, you still have to pay for certification
The only thing it takes away from you is building the system which, on time and materials basis, is not even close to the real cost of maintaining a PCI compliant system.
You also have to ensure that the data is encrypted at rest and in flight, etc. A distributed black box may pose more risks as well.
In your EC2 example, does it suffice to say "this software is PCI compliant"? Or do you and Amazon need to be PCI compliant?
This is one of the things that freaks people out about putting sensitive information in the cloud.
https://aws.amazon.com/security/pci-dss-level-1-compliance-f...
This means part of the work is done. Then if the isolated pci-blackbox you are using is also PCI-compliant in how it deals with card data, encryptions, hashes, etc, then what is left is not much, basically mostly documentation, routines in place, etc.
I would say you could probably get down to 1% of the normal work of becoming PCI-compliant by, a) Getting rid of the whole hardware part of the problem, by using EC2 and free-riding on the work already carried out by Amazon. Just make sure to use Two-Factor Authentication to access your EC2-instance.
b) Use a open sourced PCI-compliant isolated component which only handles the two bare-minimum features it needs to do, which are "encrypt and store card data" and "decrypt card and process payment via PSP".
For instance, my company has software that deals with CC info (PA-DSS), hardware that does (PTS), and we store customer CC data (PCI-DSS).
Make no mistake, PCI compliance is not easy and you have to take it seriously.
You have all of the downsides of rolling your own (liability wise) and none of the upsides of using an IPSP (also liability wise), on top of that you'd have an auditing problem. (I presume 'black box' means 'box that performs a service that you can't open up to inspect').
What you are essentially looking for here is called type certification, but type certified hardware is on small to medium volume much more expensive than a service would be. And once you hit larger volumes you're going to be hooking up a much larger number of payment options and your 'black box' will solve only a (small) subset of your needs.
I don't see the advantage of this approach.
I hope they are working on a JS integration like Stripe has though.
A form POST as their method of integration reduces my confidence level a bit.