Live data from Hacker News

Bank of England to crack down on 'secretive' cloud computing services

itnews.com.au

111–120 of 123 posts

Re: Bank of England to crack down on 'secretive' cloud computing services

#111
post #90

Earlier quoted context omitted.

I think it is unfair to think that banks don't want to do things correctly but they suffer along with all other corporates of too many levels of management to be agile, systems that are far to risky to change/replace, legacy systems and a high turnover of staff. If I ran a bank, I suspect I would run it exactly the same way because I have to.

Perhaps I'm too close to the issue as I have worked with these businesses, but I disagree. This is intentional on their part, because banks first and foremost are about identifying and managing risk. If they can find a way to mitigate that risk or externalize it, then they no longer need to deal with it head-on. Most of the risks related to IT should be dealt with head-on because they grow over time as you stay still…

>Banks will absolutely hold on to anything to avoid an unknown risk as long as they think they can hedge or mitigate known risks, and utterly fail to acknowledge the truth of unknown unknowns

Nassim Taleb has written entire books on this fact about banks. It's interesting that the same flaws in their financial thinking apply to their IT infrastructure.

Re: Bank of England to crack down on 'secretive' cloud computing services

#112
post #67

Earlier quoted context omitted.

Keep in mind it easily could at the stroke of a pen though. It's entirely their choice to not compensate competitively.

https://tipalti.com/profit-per-employee/ Visa regularly makes double the profit per employee of FAANG - so, yes, they could easily pay more.

Don't all the smart companies avoid making any profit at all, since profit is taxed (but share buybacks are not)?

Re: Bank of England to crack down on 'secretive' cloud computing services

#113

One secretive group used to dictating their own terms unhappy about another secretive group used to dictating their own terms...

The Bank of England is under the democratic control of the people of England.

The BoE is independent. That's a good thing generally - it doesn't have to bow to pressure from whatever party happens to be in power at a specific time.

Re: Bank of England to crack down on 'secretive' cloud computing services

#114
post #92

Earlier quoted context omitted.

How exactly do you figure that? Like any other quango, they are almost entirely unaccountable to anyone except their own staff. A Politician might be able to cause a stink but that's assuming they knew enough about what was going on and they probably don't.

The elected representatives of the English people could shut down the Bank tomorrow, or today.

>The elected representatives of the English people could shut down the Bank tomorrow, or today.

There is a certain irony in this statement, given that such an act would require approval from the queen.

Re: Bank of England to crack down on 'secretive' cloud computing services

#115

Earlier quoted context omitted.

Perhaps I'm too close to the issue as I have worked with these businesses, but I disagree. This is intentional on their part, because banks first and foremost are about identifying and managing risk. If they can find a way to mitigate that risk or externalize it, then they no longer need to deal with it head-on. Most of the risks related to IT should be dealt with head-on because they grow over time as you stay still…

>Banks will absolutely hold on to anything to avoid an unknown risk as long as they think they can hedge or mitigate known risks, and utterly fail to acknowledge the truth of unknown unknowns Nassim Taleb has written entire books on this fact about banks. It's interesting that the same flaws in their financial thinking apply to their IT infrastructure.

I think technology is fundamentally a tool for organizations, and as such will always evolve to reflect the larger organization. You can see this in software design and it is also seen in the IT infrastructure architecture.

Re: Bank of England to crack down on 'secretive' cloud computing services

#116

Earlier quoted context omitted.

https://tipalti.com/profit-per-employee/ Visa regularly makes double the profit per employee of FAANG - so, yes, they could easily pay more.

Don't all the smart companies avoid making any profit at all, since profit is taxed (but share buybacks are not)?

You have to buy your shares with FCF (usually profit) or debt.

They have profits. They just aren't in the US.

Re: Bank of England to crack down on 'secretive' cloud computing services

#117

Something to keep in mind here: The employees of the Bank of England are ultimately government employees. They are subjected to the pay scales dictated by bureaucrats and politicians. Of course, they can't attract the caliber of engineers that works for large commercial cloud providers, so they have to settle for programmers that didn't make the cut. And the leadership is non-technical and from the financial and gove…

From my understanding of the article, the BoE aren't concerned about their own infrastructure.

They're concerned about all the major retail banks using the same cloud provider and then that provider having a major outage.

Individual banks having an outage is an issue but one that can be handled. Three or four of the main banks all going down at once could be catastrophic.

Re: Bank of England to crack down on 'secretive' cloud computing services

#118

Earlier quoted context omitted.

The elected representatives of the English people could shut down the Bank tomorrow, or today.

>The elected representatives of the English people could shut down the Bank tomorrow, or today. There is a certain irony in this statement, given that such an act would require approval from the queen.

Let's be serious.

Re: Bank of England to crack down on 'secretive' cloud computing services

#119

Earlier quoted context omitted.

The Bank of England is under the democratic control of the people of England.

The BoE is independent. That's a good thing generally - it doesn't have to bow to pressure from whatever party happens to be in power at a specific time.

Right, most central banks have some insulation from politics. BoE's independence is granted by Parliament, and can be taken away at any time.

Re: Bank of England to crack down on 'secretive' cloud computing services

#120

Earlier quoted context omitted.

> You can actually make deterministic guarantees to your customers that not only your own systems are secure, but also that the systems of your vendors and other 3rd parties are as well. You can make a "deterministic" guarantee, whatever that is, that your systems are secure? That's seems pretty bold and probably dangerous, no?

> That's seems pretty bold and probably dangerous, no? Its not dangerous in my experience. The more dangerous angle for me is this belief that it is impossible (or hopelessly difficult) to build a secure system. The reality is that it is only possible if you are willing to take total ownership of the entire vertical. If you control every single byte that enters and exits your enterprise, you can prove that things are…

How do you know your own programmers aren't introducing security bugs? Or are even acting against your interests intentionally? It happens to every other software developer, why not you?

Do you build all your own hardware from raw materials? How do you know everyone in the supply chains is perfectly secure?

Attacks have succeeded against the CIA, against RSA, Google, and many others. Nuclear weapons plans have been stolen. I would not trust a vendor who claimed they could guarantee security.

Post reply on HN