Live data from Hacker News

Bank of England to crack down on 'secretive' cloud computing services

itnews.com.au

31–40 of 123 posts

Re: Bank of England to crack down on 'secretive' cloud computing services

#31
post #14
post #11

Earlier quoted context omitted.

While Parler is somewhat irrelevant and the likelihood of any bank being taken down for similar reasons as Parler, it isn't completely incomprehensible. There have been many horror stories of businesses being banned, blocked, or messed around by Google and Amazon. Their policy does not protect anyone but themselves. It is within the realms of reality for bank to be taken down by them in a matter of days.

Kick a UK bank off cloud infrastructure for no good reason and you will get rung up by the PM, who will make it clear that you will reinstate them or be forever banned from government procurement.

Sure, just like all the other people who have been called to parliament and suffered the consequences. Ah wait..

Our current leaders are useless in this regard. They'll be given a stern warning letter and nothing will come of it.

Re: Bank of England to crack down on 'secretive' cloud computing services

#32
post #11

Earlier quoted context omitted.

While Parler is somewhat irrelevant and the likelihood of any bank being taken down for similar reasons as Parler, it isn't completely incomprehensible. There have been many horror stories of businesses being banned, blocked, or messed around by Google and Amazon. Their policy does not protect anyone but themselves. It is within the realms of reality for bank to be taken down by them in a matter of days.

I have little doubt that the major cloud providers would be willing to contractually bind themselves to a notice and appeals period that would suffice for “because we don’t want your business anymore” reasons. The cross-bank correlated technical outages and general “fear of the new (15 years now, but continually being enhanced and changed)” is harder to get beyond.

Notice and appeals period isn't good enough. It takes UK banks millions to migrate to a cloud provider. Being given a notice period just means they have less than x amount of time to potentially spend equally as much as it took for them to get onto the cloud provider in the first place.

Re: Bank of England to crack down on 'secretive' cloud computing services

#33
post #12
post #10

The risk Bank of England doesn't like comes with the territory, and everybody who uses public cloud is subject to it. The only difference is that smaller companies don't have a big megaphone or the clout that they have, and must either accept the terms and shut up or find an alternate solution. If Bank of England wants to use their power constructively, they can literally go shopping for data center and IT companies…

> risk Bank of England doesn't like comes with the territory The BoE is the central bank; to a great extent they get to define the territory. Especially with regard to risk. Basel III and that kind of thing. > they can literally go shopping for data center and IT companies to serve their needs. No, it's not about what they themselves buy, it's about what all the banks in the UK buy. A situation where all the banks ar…

Ahh, I stand corrected.

Re: Bank of England to crack down on 'secretive' cloud computing services

#34

Earlier quoted context omitted.

> Once the risks are reviewed in open and honest ways, we find that virtually all of our clients would prefer to keep our solution on-prem. I hope this kind of risk assessment becomes more common. I'm used to people not caring until things blow up on their faces.

Well, I guess you are speaking about companies who don't know what they do. But this article speaks about banks, who have hundreds of servers, ability to recover anything, full-time employed ops teams, monitoring & automation in place for 20 years already. Moving to cloud provides very little advantage (definitely not financially) to such companies. They are not SaaS who might need to double their infrastructure over…

Its not as simple as that. Just because its the case of "we have lots of old stuff" doesn't mean you need to ignore the new stuff. Building solutions with traditional data centers and staff, even if you have a lot of it, is often a lot slower. You can spin up entire fleets of servers (or even use services such as AWS Lambda, API Gateway and DynamoDB so you never use servers) and get a solution out in much less the time. Its not just about responding to load but also to be fast enough to get new stuff out there. Traditional financial services organisations are notoriously slow to adapt to changes in the market. Using cloud resources alongside the legacy infrastructure is one way to try and remain competitive.

Re: Bank of England to crack down on 'secretive' cloud computing services

#35

Earlier quoted context omitted.

> Once the risks are reviewed in open and honest ways, we find that virtually all of our clients would prefer to keep our solution on-prem. I hope this kind of risk assessment becomes more common. I'm used to people not caring until things blow up on their faces.

Well, I guess you are speaking about companies who don't know what they do. But this article speaks about banks, who have hundreds of servers, ability to recover anything, full-time employed ops teams, monitoring & automation in place for 20 years already. Moving to cloud provides very little advantage (definitely not financially) to such companies. They are not SaaS who might need to double their infrastructure over…

Not to mention that that same infrastructure you say is in abundance is usually pretty heavily utilised already so there isn't just spare capacity lying around. Procuring new hardware can take months and if there is no rack space you are looking at more months to get that deployed.

The people that need to plan, coordinate and install all of this are also pretty heavily overworked at the moment because, believe it or not, there is a very large shortage of skilled sys admins in the world.

Using the cloud doesn't solve those problems, but it does help reduce their impact.

Re: Bank of England to crack down on 'secretive' cloud computing services

#36
post #29
post #3

We do business in the US financial sector, and the sentiment we are getting with regard to cloud vs on-prem seems to be growing into a bimodal distribution. I would say it's nearly a 50/50 split until we have conversations about how our product actually works and the incredibly sticky problem that is PII... Once the risks are reviewed in open and honest ways, we find that virtually all of our clients would prefer to…

How is the problem of PII better solved on premises?

because you can control physical access to the hardware

Re: Bank of England to crack down on 'secretive' cloud computing services

#37
post #29
post #3

We do business in the US financial sector, and the sentiment we are getting with regard to cloud vs on-prem seems to be growing into a bimodal distribution. I would say it's nearly a 50/50 split until we have conversations about how our product actually works and the incredibly sticky problem that is PII... Once the risks are reviewed in open and honest ways, we find that virtually all of our clients would prefer to…

How is the problem of PII better solved on premises?

Just my observations, but some business entities run into legal challenges that vary greatly by industry. B2B customers have a contractual relationship with you, not your hosting provider. If your hosting provider has an "oops we leaked your data" they only breached the contract with their vendor, not themselves. The contract can specify how data is managed. Adding to this, some companies/banks legal controls are compatible with SOC2 controls of a 3rd party data processor being audited and some companies are not. Some companies can cite the 3rd parties audited certifications and some can not based on preexisting legal contractual agreements with their own customers. I am not a lawyer, but had to sit in many meetings with lawyers and businesses and this is a real issue they have to address. I have also worked for a large bank. Rules, regulations and contracts around 3rd party data processors and financial institutions can get very complicated. There are a myriad of additional complicating variables that go beyond regulations. Legal obligations also vary by relationship. If a bank has preexisting relationships with other banks, they may be obligated to get approval from the other banks to change how their data is managed. Amending contracts is non-trivial. This rabbit hole can get very deep.

Re: Bank of England to crack down on 'secretive' cloud computing services

#38
post #10

The risk Bank of England doesn't like comes with the territory, and everybody who uses public cloud is subject to it. The only difference is that smaller companies don't have a big megaphone or the clout that they have, and must either accept the terms and shut up or find an alternate solution. If Bank of England wants to use their power constructively, they can literally go shopping for data center and IT companies…

The risk that they're concerned with is if every bank is using AWS, then AWS goes down, the entire UK economy crashes until it's back up.

Even if AWS itself is more reliable than every bank's on-prem solution, that's no good if it goes down for everyone simultaneously and I can't just use a backup credit card.

Re: Bank of England to crack down on 'secretive' cloud computing services

#39
post #29
post #3

We do business in the US financial sector, and the sentiment we are getting with regard to cloud vs on-prem seems to be growing into a bimodal distribution. I would say it's nearly a 50/50 split until we have conversations about how our product actually works and the incredibly sticky problem that is PII... Once the risks are reviewed in open and honest ways, we find that virtually all of our clients would prefer to…

How is the problem of PII better solved on premises?

Think about it more abstractly from the perspective of trust and # of actors involved.

If you run 100% of your IT workload on-prem, the ability to control the flow of data can be boiled down into a physical exercise of following fiber channel cables in your own datacenter. Having a unified set of firewall rules that define your entire public interface also helps a lot.

You can actually make deterministic guarantees to your customers that not only your own systems are secure, but also that the systems of your vendors and other 3rd parties are as well. The moment you start configuring site-to-site VPNs with 3rd parties across which you intend to transact sensitive business knowledge, you are surrendering an entire mountain of security constraints.

If we are being honest with ourselves, a lot of shops that are 100% on-prem probably have worse security practices than AWS, et. al. Perhaps the biggest hazard is really the hybrid model. If some fintech went 100% into the cloud without even an HSM on-prem to worry about, then you could probably have a solid argument on the other side of the spectrum. Also, remember that multi-cloud might seem like a resiliency measure, but it also adds another target to your back.

The middle ground is where all the pain seems to be. Hybrid cloud usually means more required trust than most organizations ever wanted to enter into. I frequently find myself as the harbinger of bad news when I get into deep-dive technical calls with some of our customers. Turns out a lot of the other vendors we work with like to bend the truth in order to make a quick buck. Many perverse incentives are pulling these massive organizations into hilariously-contorted IT stances, and some of us are starting to see a consulting opportunity.

Post reply on HN