Live data from Hacker News

Bank of England to crack down on 'secretive' cloud computing services

itnews.com.au

71–80 of 123 posts

Re: Bank of England to crack down on 'secretive' cloud computing services

#71
post #29
post #3

We do business in the US financial sector, and the sentiment we are getting with regard to cloud vs on-prem seems to be growing into a bimodal distribution. I would say it's nearly a 50/50 split until we have conversations about how our product actually works and the incredibly sticky problem that is PII... Once the risks are reviewed in open and honest ways, we find that virtually all of our clients would prefer to…

How is the problem of PII better solved on premises?

The surface area of vulnerabilities like spectre and meltdown is much lower

Re: Bank of England to crack down on 'secretive' cloud computing services

#72

Earlier quoted context omitted.

I know for a fact that base pay for a first year SWE with a BS+MS in CS at Goldman just broke $100k a couple years ago. That probably sounds like a lot to most people, but if you're hiring staff to live and work in NYC, especially when there's an absolutely massive Google campus 10 minutes North of the GS HQ, that's pretty much table stakes. Never mind the glaring cultural differences.

Goldman’s payday is through bonuses, not the base salary.

Only if you're in a front office role, which the vast majority of SWEs aren't.

Re: Bank of England to crack down on 'secretive' cloud computing services

#73

Earlier quoted context omitted.

Definitely agree. In my experience, the financial industry tends to lean heavily on checklists and bureaucracy to enforce security. This requires additional headcount and prevents automation. Technology companies lean the other way and enforce security through comprehensive automation of the controls they must follow.

Yes, agreed. The choking bureaucracy has the unintended consequence of lowering risk - if its very time consuming to build thing, you build less things that break over time, and rely on old things that have worked for a long time.

Intended*?

Re: Bank of England to crack down on 'secretive' cloud computing services

#74
post #39
post #29

Earlier quoted context omitted.

How is the problem of PII better solved on premises?

Think about it more abstractly from the perspective of trust and # of actors involved. If you run 100% of your IT workload on-prem, the ability to control the flow of data can be boiled down into a physical exercise of following fiber channel cables in your own datacenter. Having a unified set of firewall rules that define your entire public interface also helps a lot. You can actually make deterministic guarantees t…

> If we are being honest with ourselves, a lot of shops that are 100% on-prem probably have worse security practices than AWS, et. al.

Does it matter? You have the same freedom to fuck security up setting your AWS infrastructure as you have setting your on-prem infrastructure. All the very competent AWS staff is able to do is add less risk, they can't save you from anything.

Re: Bank of England to crack down on 'secretive' cloud computing services

#75
post #11
post #8

Earlier quoted context omitted.

That FUD is unwarranted. No bank is going to be kicked off it’s infrastructure. Bringing up Parler seems completely irrelevant.

While Parler is somewhat irrelevant and the likelihood of any bank being taken down for similar reasons as Parler, it isn't completely incomprehensible. There have been many horror stories of businesses being banned, blocked, or messed around by Google and Amazon. Their policy does not protect anyone but themselves. It is within the realms of reality for bank to be taken down by them in a matter of days.

I have my own horror story, and that's not even about the cloud, just how centralizing a service magnifies issues.

I work for near FAANG company who still sends important email information out to people. One day, many years ago, a new gmail feature landed: automatic smart tabs - and ALL of our email started landing in promotions. And those mails were send from IP addresses which were dedicated for these and only these kind of email, so we started to panic.

We started going through the correct channels for reporting this as a problem, at which point we got a "cheers, we'll get back to you in 2 weeks". At that point we were certain we were loosing money in the millions soon, so we walked over to marketing - Google PPC (pay per click) to be specific, and asked them to get hold of someone high enough at Google, we don't care how, or over what channel.

Within an hour, the change in gmail to put everything in promotions that was "noreply@" was rolled back, and our arses were saved.

If we were still in the early 2000s with countless small email servers and providers, if one of them done this, their customers would be angry at them. But since people believe Gmail is their saviour - and because nobody can get hold of anyone at google to report a problem - now it was our fault, despite the fact that we had absolutely no idea what went wrong, and there were no changes on our side.

My summary? Fuck the cloud and the centralized services; I want the small, loosely connected internet services back.

Re: Bank of England to crack down on 'secretive' cloud computing services

#76
post #39
post #29

Earlier quoted context omitted.

How is the problem of PII better solved on premises?

Think about it more abstractly from the perspective of trust and # of actors involved. If you run 100% of your IT workload on-prem, the ability to control the flow of data can be boiled down into a physical exercise of following fiber channel cables in your own datacenter. Having a unified set of firewall rules that define your entire public interface also helps a lot. You can actually make deterministic guarantees t…

> You can actually make deterministic guarantees to your customers that not only your own systems are secure, but also that the systems of your vendors and other 3rd parties are as well.

You can make a "deterministic" guarantee, whatever that is, that your systems are secure? That's seems pretty bold and probably dangerous, no?

Re: Bank of England to crack down on 'secretive' cloud computing services

#77
I think a big risk is a cpu level security issue similar to meltdown or spectre that ends up weakening the hardware isolation between tenants to the point where it can be exploited on mass on the cloud providers to wreak havoc. The probability of something like this happening is very low but not zero, I would say same level of probability as datacenter fire or earthquake banks should be planning for how to handle this type of event.

Re: Bank of England to crack down on 'secretive' cloud computing services

#78

One secretive group used to dictating their own terms unhappy about another secretive group used to dictating their own terms...

The Bank of England is under the democratic control of the people of England.

Re: Bank of England to crack down on 'secretive' cloud computing services

#79
post #67

Earlier quoted context omitted.

Bonuses are not that high at Goldman and their comp still does not compare to FAANG, it never will.

Keep in mind it easily could at the stroke of a pen though. It's entirely their choice to not compensate competitively.

https://tipalti.com/profit-per-employee/

Visa regularly makes double the profit per employee of FAANG - so, yes, they could easily pay more.

Re: Bank of England to crack down on 'secretive' cloud computing services

#80
post #11

Earlier quoted context omitted.

While Parler is somewhat irrelevant and the likelihood of any bank being taken down for similar reasons as Parler, it isn't completely incomprehensible. There have been many horror stories of businesses being banned, blocked, or messed around by Google and Amazon. Their policy does not protect anyone but themselves. It is within the realms of reality for bank to be taken down by them in a matter of days.

These things do happen, but I'd be willing to place money on it not happening to a major financial institution. The day AWS and friends summarily terminate the account of a major UK bank, causing people to lose the ability to access their money, would also be the day that every company in the country immediately pulls out the business continuity plan and digs into the section on dealing with having to migrate to a ne…

Any provider offering this kind of service is exceptionally unlikely to offboard any financial services firm without serious forethought- any outsourcing of critical processes like this would need pre-approval from the FCA and for a bank the PRA would take a hard look too.
Post reply on HN