I didn't say PSTN was secure, I said it was "more secure" than unencrypted VOIP.
Surely a PSTN call, even though it may pass through an "open, public network" at some point, surely the path will often be the same? E.g. a call from a BT customer to a Virgin Media customer will ordinarily take the same path? So you could argue it's easier to control security?
With VOIP over the internet, surely the path taken and networks passed through differs for every user depending on who their ISP is?
Not to mention other factors such as congestion or downtime which could result in BGP routing the data packets through a number of different transit providers.
My point is, surely there are more networks involved with VOIP over the internet, than a PSTN call between two telco's? Therefore it's most certainly less secure.
Please dont take this as an attack on VOIP. I use VOIP and I am a huge fan of Voipfone
As for your question, CDJ, perhaps you should put that to the PCI Security Standards Council. I agree you could argue the PCI requirement applies to both.
Ben