Another reason why the US won that race was that the extreme antisemitism in both the USSR and the Nazi regimes caused them to experience a major brain drain as a lot of scientists emigrated to the US, or were killed/imprisoned/repressed at home. Add to that the fact that US had the only industrial base that wasn't damaged by fighting and bombing, thus making it pretty close to inevitable that it would be first.

Regulations that actually accomplish something other than employing compliance officers who file reams of paperwork are necessary and a good thing. The problem comes when they morph into Byzantine rules that are self-contradictory and only serve as a jobs program for bureaucrats (both public and private) and lawyers.

Indeed. This is no different from distributing, say, a copy of Oracle's database with your code without a licensing deal. They don't require a key code to install or run it - you can download, install and run it, but without paying $17k per processor, you are in violation of their copyright.

That design tells me that you need to put a PCI-compliant hardware firewall between the POS and its associated DB server, and the rest of the internal network. And you also need to have a firewall logger that is actually looked at daily, plus you need to do vulnerability scans both internally and externally. A Windows firewall is not sufficient and won't meet PCI DSS requirements in any event, ever, and isn't going to provide any benefit if the firewall between the POS network and the rest of the store/enterprise is in place.

Any device that processes, carries, or stores ANY credit/debit card data that isn't encrypted *must* be behind a firewall that only permits it to send traffic to specific hosts that are necessary for the functioning of the system, and even then only on the bare minimum number of ports, and almost all inbound traffic is denied as well.

