Diff: FAQ #1253

Does hashing of passwords meet the intent of PCI DSS requirement 8.4?

Earlier Version
2013-07-23 00:00:00 UTC
Later Version
2014-05-29 22:19:00 UTC
Removed
Added
Using a strong hashing algorithmstrong cryptography to hash the password meets the intent of the PCI DSS rRequirement 8.42.1, which is to prevent unintentional disclosure of the passwords through suduring transmission over the network or during storage.

Please refer to the PCI DSS and PA-DSS Glossary of Terms, Abbreviations, and A
ch means as network sniffronyms for additional information on hashing.

(Note: PCI DSS Requirement numbers refer to PCI DSS version 3)