Live data from Hacker News

Bank of England to crack down on 'secretive' cloud computing services

itnews.com.au

91–100 of 123 posts

Re: Bank of England to crack down on 'secretive' cloud computing services

#91
post #24

Seems a bit like a nothing-article - doesn't make any real point. The FCA/FSA have already been noticing a lot of the financial providers placing 'all their eggs in one basket' and have been putting guidelines in place for banks to have a multi-'cloud' strategy. [0] https://www.fca.org.uk/publication/finalised-guidance/fg16-5...

That's what I thought but also, when a statement is made by a senior executive, I usually assume they don't really know what they are talking about anyway. Loads of "keynote" speeches are very hand-wavy and have a feel of importance with little of real value.

Re: Bank of England to crack down on 'secretive' cloud computing services

#92

One secretive group used to dictating their own terms unhappy about another secretive group used to dictating their own terms...

The Bank of England is under the democratic control of the people of England.

How exactly do you figure that? Like any other quango, they are almost entirely unaccountable to anyone except their own staff. A Politician might be able to cause a stink but that's assuming they knew enough about what was going on and they probably don't.

Re: Bank of England to crack down on 'secretive' cloud computing services

#93

Earlier quoted context omitted.

Yes, agreed. The choking bureaucracy has the unintended consequence of lowering risk - if its very time consuming to build thing, you build less things that break over time, and rely on old things that have worked for a long time.

Intended*?

...or intended, yes

Re: Bank of England to crack down on 'secretive' cloud computing services

#94

Does anyone know if CSPs can be managed via supplier agreements? I’ve always assumed it’s a commodity service and as such there are standard T&Cs, TOS etc. Certainly those in the financial sector wish to manage other types of supplier risk in that way where possible.

Isn't that the million dollar question (or probably billion now).

Theoretically, the Ts & Cs cover everything but clearly you cannot reasonably mitigate risk on the basis that the "supplier told me that it wouldn't happen".

You have a (sometimes legal) requirement to do due diligence and at least decide what additional controls you can have to help with compliance and what your BC/DR process is if everything really goes south.

Realistically, I don't really see AWS or Azure etc. being able to promise that their systems can never be hacked/broken. On the other hand, the assumption that doing things on-prem removes this risk is naiive since we can make just as many cock-ups even if we work for the company. Anyone ever forgotten to setup a firewall or vpn properly?

True story: When I worked at a security company, the sales team wanted to demo a digital camera-over-IP system and the IT Manager told them not to use our internal network. They ignored him and plugged it in, flooding the network with packets that took down the computers and phones for about 30 minutes until we worked out what had happened. That was inconvenient but imagine if they had plugged in something much worse "because sales"

Re: Bank of England to crack down on 'secretive' cloud computing services

#95
post #6

> But big providers could dictate terms and conditions - as well as prices - to key financial firms. What exactly is the concern here? Cloud compute is becoming cheaper over time due to market forces. Its not like Amazon is cornering the market for CPUs.

> What exactly is the concern here? Top of the article: > Concentration of compute could threaten financial stability. If BigCloud goes down, so does banking, and banking doesn't seem to like that - and I'm with them.

How is that different than the banks own systems? In the UK, we have seen about 4 or 5 really bad system failures in banks leading to unpaid salaries/bills etc. and I believe all of them were on-prem.

Sure, hedge your bets but I would hope that most people using cloud are smart enough to at least get it 95% cloud-agnostic so if price gouging occurs, they can leave.

Re: Bank of England to crack down on 'secretive' cloud computing services

#96
post #67

Earlier quoted context omitted.

Keep in mind it easily could at the stroke of a pen though. It's entirely their choice to not compensate competitively.

https://tipalti.com/profit-per-employee/ Visa regularly makes double the profit per employee of FAANG - so, yes, they could easily pay more.

Thanks for the source to backup that feeling.

Re: Bank of England to crack down on 'secretive' cloud computing services

#97
post #92

Earlier quoted context omitted.

The Bank of England is under the democratic control of the people of England.

How exactly do you figure that? Like any other quango, they are almost entirely unaccountable to anyone except their own staff. A Politician might be able to cause a stink but that's assuming they knew enough about what was going on and they probably don't.

The elected representatives of the English people could shut down the Bank tomorrow, or today.

Re: Bank of England to crack down on 'secretive' cloud computing services

#98
Something to keep in mind here: The employees of the Bank of England are ultimately government employees.

They are subjected to the pay scales dictated by bureaucrats and politicians. Of course, they can't attract the caliber of engineers that works for large commercial cloud providers, so they have to settle for programmers that didn't make the cut. And the leadership is non-technical and from the financial and government worlds (you know how these "elites" see programmers and software engineers in the UK...).

The existing bureaucrats running the bank probably see the Cloud as something that will reduce their headcount (why would they have sysadmins and datacenter employees on their payroll when they can simply buy it from a reliable provider), thus making them look less important to other managers. The existing unionized employees see it as a threat to their stable jobs (they are now competing with engineers that are 10x their caliber). That's a pretty bad thing for both.

Re: Bank of England to crack down on 'secretive' cloud computing services

#99
post #89

I think a big risk is a cpu level security issue similar to meltdown or spectre that ends up weakening the hardware isolation between tenants to the point where it can be exploited on mass on the cloud providers to wreak havoc. The probability of something like this happening is very low but not zero, I would say same level of probability as datacenter fire or earthquake banks should be planning for how to handle thi…

I don't see that this risk is any different than a similar apocolyptic failure happening to your on-prem equipment. There's not much you can do about it differently than the cloud just add some extra controls and hope for the best. I very much doubt that anyone would not use the cloud because of a theoretical de-isolation bug. Also, by the time you found out, it would probably already be too late anyway if you were a…

I am not saying that they should not use cloud just that it is important to have a plan in place to deal with a unlikely but high impact security event affecting a cloud provider. Just like companies have business continuity plans in case a data center disaster they need to have plans for evacuate a cloud provider should they need too.

I put on my seat belt when I drive on the highways even though a nasty crash at 120 kph would likely kill me. Not using a seat belt because you will be severely injured anyway is not wise.

Given the amount of profit banks make what is the Downside of having them be resilient against public cloud failures?

Re: Bank of England to crack down on 'secretive' cloud computing services

#100

I think a big risk is a cpu level security issue similar to meltdown or spectre that ends up weakening the hardware isolation between tenants to the point where it can be exploited on mass on the cloud providers to wreak havoc. The probability of something like this happening is very low but not zero, I would say same level of probability as datacenter fire or earthquake banks should be planning for how to handle thi…

Separate hardware for your stuff is a standard AWS product, for example - you can just buy this.

That’s one way of dealing with hardware isolation risk but not every bank is doing this on public cloud.
Post reply on HN