<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How To Be PCI Compliant in the Cloud&#8230;</title>
	<atom:link href="http://www.rationalsurvivability.com/blog/?feed=rss2&#038;p=5" rel="self" type="application/rss+xml" />
	<link>http://www.rationalsurvivability.com/blog/?p=5</link>
	<description>Hoff&#039;s Ramblings about Information Survivability, Information Centricity, Risk Management and Disruptive Innovation. Oh, I have a fondness for virtualization and cloud computing security, too...</description>
	<lastBuildDate>Thu, 09 Sep 2010 02:54:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Dear Verizon Business: I Have Some Questions About Your PCI-Compliant Cloud&#8230; &#124; Rational Survivability</title>
		<link>http://www.rationalsurvivability.com/blog/?p=5&#038;cpage=1#comment-48367</link>
		<dc:creator>Dear Verizon Business: I Have Some Questions About Your PCI-Compliant Cloud&#8230; &#124; Rational Survivability</dc:creator>
		<pubDate>Wed, 25 Aug 2010 03:31:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=5#comment-48367</guid>
		<description>[...] but the last time I saw a similar claim of a PCI compliant Cloud offering, it turned out rather anti-climatically for RackSpace/Mosso, so I just want to make sure I understand what is really being said.  I may be mixing things up in [...]</description>
		<content:encoded><![CDATA[<p>[...] but the last time I saw a similar claim of a PCI compliant Cloud offering, it turned out rather anti-climatically for RackSpace/Mosso, so I just want to make sure I understand what is really being said.  I may be mixing things up in [...]</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-48367" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('48367', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-48367-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-48367" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('48367', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-48367-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Calling All Private Cloud Haters: Amazon Just Peed On Your Fire Hydrant&#8230; &#124; Rational Survivability</title>
		<link>http://www.rationalsurvivability.com/blog/?p=5&#038;cpage=1#comment-13487</link>
		<dc:creator>Calling All Private Cloud Haters: Amazon Just Peed On Your Fire Hydrant&#8230; &#124; Rational Survivability</dc:creator>
		<pubDate>Wed, 26 Aug 2009 09:20:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=5#comment-13487</guid>
		<description>[...] Further, it should be noted that now that the 800lb Gorilla has staked a flag, this will bring up all sorts of additional auditing and compliance questions, as any sort of broad connectivity into and out of security zones and asset groupings always do.  See the PCI debate (How to Be PCI Compliant In the Cloud) [...]</description>
		<content:encoded><![CDATA[<p>[...] Further, it should be noted that now that the 800lb Gorilla has staked a flag, this will bring up all sorts of additional auditing and compliance questions, as any sort of broad connectivity into and out of security zones and asset groupings always do.  See the PCI debate (How to Be PCI Compliant In the Cloud) [...]</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-13487" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('13487', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-13487-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-13487" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('13487', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-13487-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: PhilA</title>
		<link>http://www.rationalsurvivability.com/blog/?p=5&#038;cpage=1#comment-2081</link>
		<dc:creator>PhilA</dc:creator>
		<pubDate>Fri, 20 Mar 2009 08:14:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=5#comment-2081</guid>
		<description>Educate me here, how should Mosso/RackSpace word their pitch to not entice this response?

Many of the cloud providers are headed towards their marketing approach.</description>
		<content:encoded><![CDATA[<p>Educate me here, how should Mosso/RackSpace word their pitch to not entice this response?</p>
<p>Many of the cloud providers are headed towards their marketing approach.</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-2081" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('2081', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-2081-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-2081" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('2081', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-2081-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: beaker</title>
		<link>http://www.rationalsurvivability.com/blog/?p=5&#038;cpage=1#comment-2055</link>
		<dc:creator>beaker</dc:creator>
		<pubDate>Tue, 17 Mar 2009 13:20:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=5#comment-2055</guid>
		<description>&lt;a href=&quot;#comment-2013&quot; rel=&quot;nofollow&quot;&gt;@Philip Murphy&lt;/a&gt; 

Phillip:

Thanks very much for the comment. 

I don&#039;t doubt the business case and support you&#039;ve received from Mosso as certainly it reflects the value of the Cloud. What is important to us security wonks is that we make absolutely clear that when a provider suggests they &quot;enabled&quot; PCI compliance, that we clarify what that means.

We&#039;re slightly allergic to that sort of language in our world: &quot;Buy our product/service and BAM! You&#039;re compliant.&quot;

Mosso has every right to market as they see fit, but we&#039;re going to call a spade a spade here.

I am thrilled that Mosso gives you excellent service and value, but some of the messaging here is suspect.

Thanks again for commenting.

/Hoff</description>
		<content:encoded><![CDATA[<p><a href="#comment-2013" rel="nofollow">@Philip Murphy</a> </p>
<p>Phillip:</p>
<p>Thanks very much for the comment. </p>
<p>I don&#8217;t doubt the business case and support you&#8217;ve received from Mosso as certainly it reflects the value of the Cloud. What is important to us security wonks is that we make absolutely clear that when a provider suggests they &#8220;enabled&#8221; PCI compliance, that we clarify what that means.</p>
<p>We&#8217;re slightly allergic to that sort of language in our world: &#8220;Buy our product/service and BAM! You&#8217;re compliant.&#8221;</p>
<p>Mosso has every right to market as they see fit, but we&#8217;re going to call a spade a spade here.</p>
<p>I am thrilled that Mosso gives you excellent service and value, but some of the messaging here is suspect.</p>
<p>Thanks again for commenting.</p>
<p>/Hoff</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-2055" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('2055', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-2055-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-2055" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('2055', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-2055-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Philip Murphy</title>
		<link>http://www.rationalsurvivability.com/blog/?p=5&#038;cpage=1#comment-2013</link>
		<dc:creator>Philip Murphy</dc:creator>
		<pubDate>Mon, 16 Mar 2009 21:30:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=5#comment-2013</guid>
		<description>I just wanted to say that from a business perspective, Mosso&#039;s solution is a perfect fit for us.
Truth be told, we previously used a hybrid solution like the one we are using at Mosso with a dedicated server. From our perspective, this was an expensive solution that was not scalable and required us to maintain the server ourselves, as well as pay for excess capacity.
While Mosso&#039;s solution may not be appropriate for large enterprises, it works for us. The stumbling block we encountered with our desire to move into cloud hosting was passing the vulnerabilty scans. Mosso&#039;s platform let us do that.
It is true that the technology is not new. I think what is new is that we asked Mosso to &quot;fix&quot; the vulnerabilities found in our ASV scans and they worked with us to do so. They also detailed a specific set of steps for other e-commerce merchants to follow in order to pass the scans and become compliant.
Previously, from a business perspective there was a thought that one had to use a dedicated server (even if using a hybrid solution like the one described by Mosso) in order to pass the ASV scans AND allow for some level of scalability and traffic spikes. This solution provided by Mosso let us move from a dedicated solution to a more cost-effective and scalable one.
It may not be a new technology but the ability to use some solution other than a dedicated server was new for us from a business standpoint.
Best regards,
Philip Murphy
VP Operations
The Spreadsheet Store
</description>
		<content:encoded><![CDATA[<p>I just wanted to say that from a business perspective, Mosso&#8217;s solution is a perfect fit for us.<br />
Truth be told, we previously used a hybrid solution like the one we are using at Mosso with a dedicated server. From our perspective, this was an expensive solution that was not scalable and required us to maintain the server ourselves, as well as pay for excess capacity.<br />
While Mosso&#8217;s solution may not be appropriate for large enterprises, it works for us. The stumbling block we encountered with our desire to move into cloud hosting was passing the vulnerabilty scans. Mosso&#8217;s platform let us do that.<br />
It is true that the technology is not new. I think what is new is that we asked Mosso to &#8220;fix&#8221; the vulnerabilities found in our ASV scans and they worked with us to do so. They also detailed a specific set of steps for other e-commerce merchants to follow in order to pass the scans and become compliant.<br />
Previously, from a business perspective there was a thought that one had to use a dedicated server (even if using a hybrid solution like the one described by Mosso) in order to pass the ASV scans AND allow for some level of scalability and traffic spikes. This solution provided by Mosso let us move from a dedicated solution to a more cost-effective and scalable one.<br />
It may not be a new technology but the ability to use some solution other than a dedicated server was new for us from a business standpoint.<br />
Best regards,<br />
Philip Murphy<br />
VP Operations<br />
The Spreadsheet Store</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-2013" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('2013', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-2013-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-2013" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('2013', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-2013-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Craig Balding</title>
		<link>http://www.rationalsurvivability.com/blog/?p=5&#038;cpage=1#comment-2</link>
		<dc:creator>Craig Balding</dc:creator>
		<pubDate>Sun, 15 Mar 2009 21:36:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=5#comment-2</guid>
		<description>@Chris - thanks for the link love and kind words - much appreciated.  Let me know when your @source Boston preso/recording is available - from the feedback I&#039;ve heard so far, it sounds really good and I&#039;d like to ensure my readers get to see it.
</description>
		<content:encoded><![CDATA[<p>@Chris &#8211; thanks for the link love and kind words &#8211; much appreciated.  Let me know when your @source Boston preso/recording is available &#8211; from the feedback I&#8217;ve heard so far, it sounds really good and I&#8217;d like to ensure my readers get to see it.</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-2" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('2', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-2-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-2" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('2', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-2-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Bret Piatt</title>
		<link>http://www.rationalsurvivability.com/blog/?p=5&#038;cpage=1#comment-3</link>
		<dc:creator>Bret Piatt</dc:creator>
		<pubDate>Sun, 15 Mar 2009 21:08:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=5#comment-3</guid>
		<description>You can use SIM with Cloud Sites, not AIM.  A good part of the reason for marketing this is to help drive awareness in the merchant community of easier ways to solve PCI so they can do what they want -- sell merchandise.
Right now a large portion of the merchant community believes either (a) you use some sort of shared storefront offering like Yahoo! Stores, Volusion, Amazon, eBay, or (b) you have to go build an expensive dedicated environment that contains all of the controls for a Type 5/SAQ D environment.
We want to help educate that you can have a flexible and scalable front end web architecture and a use a payment partner for the cardholder data giving you the majority of the benefits of a dedicated Type 5 environment without much of the direct expense.
We&#039;re going to continue adding security into the cloud as the scalability, speed, and stability allow.  Without the latter 3 Ss I&#039;m not sure if anyone cares if it has super duper security features.
Bret Piatt
Rackspace Hosting
</description>
		<content:encoded><![CDATA[<p>You can use SIM with Cloud Sites, not AIM.  A good part of the reason for marketing this is to help drive awareness in the merchant community of easier ways to solve PCI so they can do what they want &#8212; sell merchandise.<br />
Right now a large portion of the merchant community believes either (a) you use some sort of shared storefront offering like Yahoo! Stores, Volusion, Amazon, eBay, or (b) you have to go build an expensive dedicated environment that contains all of the controls for a Type 5/SAQ D environment.<br />
We want to help educate that you can have a flexible and scalable front end web architecture and a use a payment partner for the cardholder data giving you the majority of the benefits of a dedicated Type 5 environment without much of the direct expense.<br />
We&#8217;re going to continue adding security into the cloud as the scalability, speed, and stability allow.  Without the latter 3 Ss I&#8217;m not sure if anyone cares if it has super duper security features.<br />
Bret Piatt<br />
Rackspace Hosting</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-3-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-3-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Peter Bell</title>
		<link>http://www.rationalsurvivability.com/blog/?p=5&#038;cpage=1#comment-4</link>
		<dc:creator>Peter Bell</dc:creator>
		<pubDate>Sun, 15 Mar 2009 20:55:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=5#comment-4</guid>
		<description>Just because the site isn&#039;t *storing* cc info, doesn&#039;t mean it is out of scope for PCI. If they store, transmit or process the cc data, surely the site is in scope? That means that if they use (say) auth.net&#039;s simple checkout where the user enters their cc into the auth.net server, they are out of scope, but if they host a form that returns to their server and then calls auth.net using AIM, their website is IN scope.
Could you clarify whether the site you&#039;re mentioning is using simple or advanced integraiton (do they host the cc page and transmit the cc data to auth.net)? If so, it also seems to me that the press release is saying that they helped them to pass the approved scanning process which is only one of the requirements for actually being PCI compliant if the site is in scope.
Looking forwards to learning more!
</description>
		<content:encoded><![CDATA[<p>Just because the site isn&#8217;t *storing* cc info, doesn&#8217;t mean it is out of scope for PCI. If they store, transmit or process the cc data, surely the site is in scope? That means that if they use (say) auth.net&#8217;s simple checkout where the user enters their cc into the auth.net server, they are out of scope, but if they host a form that returns to their server and then calls auth.net using AIM, their website is IN scope.<br />
Could you clarify whether the site you&#8217;re mentioning is using simple or advanced integraiton (do they host the cc page and transmit the cc data to auth.net)? If so, it also seems to me that the press release is saying that they helped them to pass the approved scanning process which is only one of the requirements for actually being PCI compliant if the site is in scope.<br />
Looking forwards to learning more!</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-4-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-4-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: beaker</title>
		<link>http://www.rationalsurvivability.com/blog/?p=5&#038;cpage=1#comment-5</link>
		<dc:creator>beaker</dc:creator>
		<pubDate>Sun, 15 Mar 2009 19:38:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=5#comment-5</guid>
		<description>Emil:
I appreciate your comments.  I also appreciate the marketing efforts that went in to this announcement, but I respectfully suggest that our definitions of &quot;transparency&quot; given the &quot;simplexity&quot; of the solution presented by The Spreadsheet Store example are not congruent.
Clearly we agree about the hybrid nature of Cloud and its benefits, but we&#039;re going to end up with Clouds on Clouds on Clouds and while you&#039;re piece of the pie may &quot;enable&quot; (in your words) PCI compliance, it&#039;s really just one move in a complex shell game of attempting to reassign/transfer risk.
This isn&#039;t YOUR shell game, you&#039;re just playing it, but while you provide an excellent service that I happen to like very much, what exactly have you done with Cloud Sites from a service delivery and technology perspective that someone else could not by simply redirecting the credit card in-scope data from touching their resources?
Is it really that you&#039;re just the first to point out the obvious or can you explain more about how this is so markedly different from everyone else?
I&#039;m NOT trying to be antagonistic, but if we&#039;re going to discuss this, I&#039;d like to distill it down for my readers.
/Hoff
</description>
		<content:encoded><![CDATA[<p>Emil:<br />
I appreciate your comments.  I also appreciate the marketing efforts that went in to this announcement, but I respectfully suggest that our definitions of &#8220;transparency&#8221; given the &#8220;simplexity&#8221; of the solution presented by The Spreadsheet Store example are not congruent.<br />
Clearly we agree about the hybrid nature of Cloud and its benefits, but we&#8217;re going to end up with Clouds on Clouds on Clouds and while you&#8217;re piece of the pie may &#8220;enable&#8221; (in your words) PCI compliance, it&#8217;s really just one move in a complex shell game of attempting to reassign/transfer risk.<br />
This isn&#8217;t YOUR shell game, you&#8217;re just playing it, but while you provide an excellent service that I happen to like very much, what exactly have you done with Cloud Sites from a service delivery and technology perspective that someone else could not by simply redirecting the credit card in-scope data from touching their resources?<br />
Is it really that you&#8217;re just the first to point out the obvious or can you explain more about how this is so markedly different from everyone else?<br />
I&#8217;m NOT trying to be antagonistic, but if we&#8217;re going to discuss this, I&#8217;d like to distill it down for my readers.<br />
/Hoff</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-5" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('5', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-5-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-5" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('5', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-5-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Emil Sayegh</title>
		<link>http://www.rationalsurvivability.com/blog/?p=5&#038;cpage=1#comment-6</link>
		<dc:creator>Emil Sayegh</dc:creator>
		<pubDate>Sun, 15 Mar 2009 19:22:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=5#comment-6</guid>
		<description>This was posted on another blog that raised the same issues.
&quot;As you clearly state, we (Mosso) were very transparent in indicating what information is stored on our Cloud and what is not.
The truth is that we are the first Cloud, that we know of, that enabled its Cloud customers to gain PCI compliance using multiple technologies. The future of Cloud technologies is full of these types of hybrid solutions that combine the best of both worlds. The goal for a customer and online merchant, is to get PCI compliance, not be purist in terms of technology. On line merchants want to leverage the Cloud for scaling, and this is a good way to do it by combining both worlds.
The fact that some people knew it was possible, but not executed should not take away from the fact that Mosso was the first one to bring it to market, and execute. A lot of work had to go on from the Mosso side to enable this. There was work involved with the payment gateways to find the best solution for our customers. Also there was work involved with our system to demonstrate compliance with the merchant perimeter scans, something that no other cloud provider has done, to the best of our knowledge.
We are very pragmatic in our approach, and will use the best of both worlds (Hybrid: Cloud/Dedicated) to bring solutions to our customers that can help them, today.
I hope all this helps. Thanks again, and let us if you have further questions. My email is ghrncir@mosso.com.
Greg Hrncir (ghrncir@mosso.com)
Director of Operations
Mosso &#124; The Rackspace Cloud&quot;
Anyone with more questions can also feel free to reach out to me.
Emil Sayegh,
General Manager
Mosso &#124; The Rackspace Cloud
(esayegh@mosso.com)
</description>
		<content:encoded><![CDATA[<p>This was posted on another blog that raised the same issues.<br />
&#8220;As you clearly state, we (Mosso) were very transparent in indicating what information is stored on our Cloud and what is not.<br />
The truth is that we are the first Cloud, that we know of, that enabled its Cloud customers to gain PCI compliance using multiple technologies. The future of Cloud technologies is full of these types of hybrid solutions that combine the best of both worlds. The goal for a customer and online merchant, is to get PCI compliance, not be purist in terms of technology. On line merchants want to leverage the Cloud for scaling, and this is a good way to do it by combining both worlds.<br />
The fact that some people knew it was possible, but not executed should not take away from the fact that Mosso was the first one to bring it to market, and execute. A lot of work had to go on from the Mosso side to enable this. There was work involved with the payment gateways to find the best solution for our customers. Also there was work involved with our system to demonstrate compliance with the merchant perimeter scans, something that no other cloud provider has done, to the best of our knowledge.<br />
We are very pragmatic in our approach, and will use the best of both worlds (Hybrid: Cloud/Dedicated) to bring solutions to our customers that can help them, today.<br />
I hope all this helps. Thanks again, and let us if you have further questions. My email is <a href="mailto:ghrncir@mosso.com">ghrncir@mosso.com</a>.<br />
Greg Hrncir (ghrncir@mosso.com)<br />
Director of Operations<br />
Mosso | The Rackspace Cloud&#8221;<br />
Anyone with more questions can also feel free to reach out to me.<br />
Emil Sayegh,<br />
General Manager<br />
Mosso | The Rackspace Cloud<br />
(esayegh@mosso.com)</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-6-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-6-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Janke</title>
		<link>http://www.rationalsurvivability.com/blog/?p=5&#038;cpage=1#comment-7</link>
		<dc:creator>Michael Janke</dc:creator>
		<pubDate>Sun, 15 Mar 2009 18:20:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=5#comment-7</guid>
		<description>&lt;i&gt;&quot;instead re-direct/use someone else&#039;s service&quot;&lt;/i&gt;
I&#039;ve always been a strong proponent of that solution, and implemented it long before PCI existed. (a decade ago? - can&#039;t remember)
So now lets ask a dumb question. If you are outsourcing you storefront hosting to a cloud provider, and you are using off the shelf storefront software shopping cart software, and you are outsourcing card processing to another service, why not just outsource the entire mess to Digital River or someone like that? Who the heck wants to manage a daisy chain of strung-together outsourcers?
While I&#039;m at it, I&#039;ll ask another dumb question. If the cloud provider can&#039;t directly host card data because they don&#039;t meet the compliance regime, why would I trust them to host the rest of my customers private data? Doesn&#039;t that data also need protection roughly equivalent to card data?
&lt;b&gt;I sure think it does.&lt;/b&gt; Identity theft is a far large problem for an individual that credit card theft, especially when you are doing dumb things like storing mothers maiden name, place of birth and other identity-theft targets.
You can&#039;t simply revoke your identity and get a new one in the mail 3 days later.
</description>
		<content:encoded><![CDATA[<p><i>&#8220;instead re-direct/use someone else&#8217;s service&#8221;</i><br />
I&#8217;ve always been a strong proponent of that solution, and implemented it long before PCI existed. (a decade ago? &#8211; can&#8217;t remember)<br />
So now lets ask a dumb question. If you are outsourcing you storefront hosting to a cloud provider, and you are using off the shelf storefront software shopping cart software, and you are outsourcing card processing to another service, why not just outsource the entire mess to Digital River or someone like that? Who the heck wants to manage a daisy chain of strung-together outsourcers?<br />
While I&#8217;m at it, I&#8217;ll ask another dumb question. If the cloud provider can&#8217;t directly host card data because they don&#8217;t meet the compliance regime, why would I trust them to host the rest of my customers private data? Doesn&#8217;t that data also need protection roughly equivalent to card data?<br />
<b>I sure think it does.</b> Identity theft is a far large problem for an individual that credit card theft, especially when you are doing dumb things like storing mothers maiden name, place of birth and other identity-theft targets.<br />
You can&#8217;t simply revoke your identity and get a new one in the mail 3 days later.</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-7-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-7-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
</channel>
</rss>
