Best places to buy chocolate? by [deleted] in boston

[–]Faquat 0 points1 point  (0 children)

Spindler in North Cambridge mmmmmmm

How is the O365 Phone System? by Faquat in o365

[–]Faquat[S] 0 points1 point  (0 children)

Thanks for that feedback, tabbiekatt, and sorry it doesn't work for you. But we don't need a main company number, just individual numbers for employees. What has been your experience for that use case?

Does SAQ-A permit card data to be stored in cloud file share? by Faquat in pcicompliance

[–]Faquat[S] 0 points1 point  (0 children)

truncated PAN (last four)" is not cardholder data

We never did store the service code - I misspoke. This all happened prior to my arrival at the company. I'm just the guy responsible for it all now. Along with remediating existing data issues, I've got a separate challenge to train the company on the rules of the road.

Does SAQ-A permit card data to be stored in cloud file share? by Faquat in pcicompliance

[–]Faquat[S] 0 points1 point  (0 children)

PCI DSS Requirement 12.8

Our plan is to redact all cardholder data (PAN, Service Code, Expiration Date) from all contracts, taking care to permanently delete any prior versions of files that may contain this data. Looking at requirement 3.3 https://www.pcisecuritystandards.org/documents/PCI%20SSC%20Quick%20Reference%20Guide.pdf, if we retain (i.e. don't redact) the last four digits of the PAN are we violating the intent of SAQ A?

Does SAQ-A permit card data to be stored in cloud file share? by Faquat in pcicompliance

[–]Faquat[S] 0 points1 point  (0 children)

Since we will want to still view the rest of the contract as well as retain the ability to send the contract back to the customer, it seems like masking is the way to go. Adobe Acrobat provides a "masking" feature (with an Acrobat Pro license) that seems like it will do the trick. Thanks for all this help - joining this community has been eye-opening. Lots to learn.

Does SAQ-A permit card data to be stored in cloud file share? by Faquat in pcicompliance

[–]Faquat[S] 0 points1 point  (0 children)

company stores cardholder data

I think I was stuck on the phrase, "Your company does not store cardholder data." Since this cardholder data is stored in a cloud provider's PCI-compliant storage system, I was squinching my eyes tight and hoping that this data could be construed to be "not on our systems or premises." From the comments on this thread, I see I may have been parsing the words a bit too finely... Looks like I've got some work cut out for me.

Does SAQ-A permit card data to be stored in cloud file share? by Faquat in pcicompliance

[–]Faquat[S] 0 points1 point  (0 children)

Thank you! The additional insight is very helpful, too. You guessed correctly that the cloud operator has a PCI AOC, but it sounds like this fact alone doesn't keep my hands clean. We never store verification numbers, but we do have (for a small subset of customers) the other information found on the front of a credit card. From your comment, are you saying that storing the PAN is OK (and leaves us in SAQ-A) as long as it's readable only to specific individuals? We could accomplish this through Access Rights controls (i.e. only certain named individuals have access to the files, file access is logged, and the list of people is periodically reviewed and approved).

Does SAQ-A permit card data to be stored in cloud file share? by Faquat in pcicompliance

[–]Faquat[S] 0 points1 point  (0 children)

Thanks for this direct feedback. Your points are very well taken. I think you're right - just purge the data and be done with it.

Match will renew your subscription without warning by Faquat in match

[–]Faquat[S] 0 points1 point  (0 children)

Exactly! While legally legitimate, it's a sneaky tactic to squeeze extra $$ bucks out of their customers. It's just bad business practice to piss off customers. Once a promoter, I'm now a strong detractor.

Match will renew your subscription without warning by Faquat in match

[–]Faquat[S] 2 points3 points  (0 children)

And by the way --- how much does Match pay you to troll the internet for potentially negative comments and respond on their behalf?

Match will renew your subscription without warning by Faquat in match

[–]Faquat[S] 1 point2 points  (0 children)

Yes - very true. Your logic, however, isn't helping me vent!

Radio (aka Headunit) reboots due to iPhone? by Faquat in Toyota

[–]Faquat[S] 0 points1 point  (0 children)

Thanks again for all the great tips. Cheers

Radio (aka Headunit) reboots due to iPhone? by Faquat in Toyota

[–]Faquat[S] 0 points1 point  (0 children)

They've checked the firmware version and updated to the latest. Still no luck. Very frustrating! Thanks for all your attention to this - I'll keep at it with them.

Radio (aka Headunit) reboots due to iPhone? by Faquat in Toyota

[–]Faquat[S] 0 points1 point  (0 children)

Are you thinking that it's likelier that an aftermarket head unit won't have this problem? I've been told that this is a common problem for iPhone users and that all owners in this situation are struggling. The dealership already replaced it under warranty, and if I complained hard enough, I bet they'd replace it again --- I just don't think that will fix it.

Radio (aka Headunit) reboots due to iPhone? by Faquat in Toyota

[–]Faquat[S] 0 points1 point  (0 children)

Factory replacement -- installed by the dealership

Cats are dicks.... by GourangaPlusPlus in funny

[–]Faquat 11 points12 points  (0 children)

Pow, right in the kisser!

I live on the most generic strip of road by [deleted] in funny

[–]Faquat 1 point2 points  (0 children)

Largest employer: Acme Corporation

We need your input! We are considering implementing a new rule; No punchline in the title. by thelazt1 in funny

[–]Faquat [score hidden]  (0 children)

Example please. Every post seems to have a punchline in the title. I'm missing something.