Why is the browser not sending cookies with cross-domain WebSocket handshake request?

If I have understood Cross-Site WebSocket Hijacking (CSWSH) attack correctly [1][2][3][4], the attack relies on two things (examples are from the first reference):

the browser sending the cookies set by the victim domain (www.some-trading… Continue reading Why is the browser not sending cookies with cross-domain WebSocket handshake request?

PIN delivery: do PCI DSS requirements prevent sending the PIN to an end-user’s mobile phone?

Do PCI DSS requirements prevent processors from sending to endusers’ mobile phones the PIN?
I went through many PCI documents, such as the PCI security requirements 2.0 and this isn’t mentioned. I’m not sure this is mentioned… Continue reading PIN delivery: do PCI DSS requirements prevent sending the PIN to an end-user’s mobile phone?