Live data from Hacker News

How we secure Monzo's banking platform

monzo.com

91–100 of 148 posts

Re: How we secure Monzo's banking platform

#91
post #28

Disgruntled former Monzo customer here. Do they still have a haywire fraud detection system that randomly freezes innocent people's accounts? It's happened to countless users and the customer experience when they do it ("we refuse to tell you why" and in some cases holding onto their money for months) is a kafkaesque nightmare. https://www.vice.com/en/article/bvg7n3/monzo-freezing-closin... https://www.reddit.com/r/U…

No UK bank will ever tell you why your account is frozen, and this is why: https://www.cps.gov.uk/legal-guidance/money-laundering-offen... . Source: used to work on Monzo's financial crime team.

The concerning thing is that the other commenter says it took him a year and a complaint to the financial ombudsman to recover his money.

False positives are one thing, but it shouldn't take a year to resolve?

Re: How we secure Monzo's banking platform

#92
post #83

Should banking really be on a cloud platform? I do believe AWS is likely far more secure than any DIY computing environment but even so, should banking be on cloud infrastructure? I'm not saying I think this is a bad idea but it came to mind when I read this. Also, is it really a good idea for a bank to be talking openly about its security strategy? Isn't an important part of security not to let on anything that migh…

How else would you scale to meet peak demand without being wasteful? Banking has a fairly predictable usage pattern, but there will be black swan financial events that cause 100-1000x load. On top of that, how else could you serve customers around the globe with reasonable latencies? These are genuine questions. I’ll admit I’m an engineer whose entire career has been during the cloud era. I don’t see how cloud’s adva…

> How else would you scale to meet peak demand without being wasteful?

I can only speak to the banks I've have the opportunity to work with who stayed on prem or built their own internal cloud infra; what you call waste, they consider a premium/cost of business for security and resilience. I'm sure a lot of folks would've said the same thing about JIT supply chains (that had been squeezed to be as efficient as possible) until they unraveled.

> I don’t see how cloud’s advantages of scaling and worldwide “edge” locations can be replicated by the average bank’s tech team.

As always, "what are your requirements and what are you optimizing for?" Most folks don't need web scale nor edge locations [1] [2], they'll get by just fine with a CDN and some API endpoints [3].

[1] https://news.ycombinator.com/item?id=19576092

[2] https://blog.bradfieldcs.com/you-are-not-google-84912cf44afb

[3] http://mcfunley.com/choose-boring-technology

Re: How we secure Monzo's banking platform

#93
post #28

Disgruntled former Monzo customer here. Do they still have a haywire fraud detection system that randomly freezes innocent people's accounts? It's happened to countless users and the customer experience when they do it ("we refuse to tell you why" and in some cases holding onto their money for months) is a kafkaesque nightmare. https://www.vice.com/en/article/bvg7n3/monzo-freezing-closin... https://www.reddit.com/r/U…

> Do they still have a haywire fraud detection system that randomly freezes innocent people's accounts? I As others have pointed out already, AML/KYC laws are strict. They are strict in general for financial services, but for banks, because of their privileged position in the financial system, its even stricter. But there is a second aspect which is that challenger banks such as Monzo take an even more cookie-cutter…

Is it Andrews & Arnold? I remember their director blogging about moving the business to Monzo so they can get real-time webhooks for incoming payments. I've just checked and they still appear to be using Monzo as per their "bank details" page.

Re: How we secure Monzo's banking platform

#94
post #8

> more than 20,000 containerised workloads across more than 2000 microservices to date. This is insane . What am I missing here that an organization is bragging about having 2000 moving parts?

Not sure they're bragging about it - they're just stating it as context for their blog post. And is 2000 moving parts too many? How many moving parts do you need to run a bank? I can imagine they're having to comply with ~2000 legislation clauses, for example. Isn't that just the complexity of their domain?

From my understanding the approach to microservices was more or less a day 1 thing due to some of the early engineering hires being very experienced with them; so the number of them was comparatively high pretty early on.

Re: How we secure Monzo's banking platform

#95
post #65

Earlier quoted context omitted.

Happy Monzo customer here with it as my primary account for the last 2 years. Haven’t had any issues, and neither have any of my friends. It’s the best possible banking experience imo. I’m happy they are proactive about suspicious activity.

Sounds like a paid “amazon” review. lul

Probably works at Monzo

Re: How we secure Monzo's banking platform

#96
post #83

Earlier quoted context omitted.

How else would you scale to meet peak demand without being wasteful? Banking has a fairly predictable usage pattern, but there will be black swan financial events that cause 100-1000x load. On top of that, how else could you serve customers around the globe with reasonable latencies? These are genuine questions. I’ll admit I’m an engineer whose entire career has been during the cloud era. I don’t see how cloud’s adva…

> How else would you scale to meet peak demand without being wasteful? I can only speak to the banks I've have the opportunity to work with who stayed on prem or built their own internal cloud infra; what you call waste, they consider a premium/cost of business for security and resilience. I'm sure a lot of folks would've said the same thing about JIT supply chains (that had been squeezed to be as efficient as possib…

Are there many examples of companies (today) building 1000x the infrastructure they normally need? I can see how it could be necessary for some companies.

> Most folks don't need web scale nor edge locations [1] [2], they'll get by just fine with a CDN and some API endpoints [3]

Isn’t using a CDN using cloud?

Re: How we secure Monzo's banking platform

#97
post #96

Earlier quoted context omitted.

> How else would you scale to meet peak demand without being wasteful? I can only speak to the banks I've have the opportunity to work with who stayed on prem or built their own internal cloud infra; what you call waste, they consider a premium/cost of business for security and resilience. I'm sure a lot of folks would've said the same thing about JIT supply chains (that had been squeezed to be as efficient as possib…

Are there many examples of companies (today) building 1000x the infrastructure they normally need? I can see how it could be necessary for some companies. > Most folks don't need web scale nor edge locations [1] [2], they'll get by just fine with a CDN and some API endpoints [3] Isn’t using a CDN using cloud?

[deleted]

Re: How we secure Monzo's banking platform

#98

Earlier quoted context omitted.

No UK bank will ever tell you why your account is frozen, and this is why: https://www.cps.gov.uk/legal-guidance/money-laundering-offen... . Source: used to work on Monzo's financial crime team.

The concerning thing is that the other commenter says it took him a year and a complaint to the financial ombudsman to recover his money. False positives are one thing, but it shouldn't take a year to resolve?

I suspect this is more to do with the financial regulation & the bodies that investigate these things, rather than Monzo.

Re: How we secure Monzo's banking platform

#99

Earlier quoted context omitted.

Others replying here are jumping to conclusions. A frozen account could be due to any number of things. The customer service person may or may not have access to the reasons. In any case, it might be money laundering (from the bank’s perspective), therefore they can’t tell you anything. Of course this is ridiculous. Due process should exist, even when a private organization “accuses” someone of illegal activity.

The law is really strict. If you look on reddit.com/r/ukpersonalfinance there's loads of people complaining that Monzo have frozen accounts and won't tell you way. In pretty much every circumstance, the person involved has been moving large amounts of money around through Crypto, so it's fairly obvious why they might flag that up as potential fraud/money laundering and cause an investigation.

I'm in the process of trying to open a UK business bank account for myself and two other directors. The hoops we have to jump through are insane.

Re: How we secure Monzo's banking platform

#100

Earlier quoted context omitted.

>That's more or less the same question as "what if the data center/servers operated by the bank gets compromised". The difference is that cloud relies on public services, which once compromised (e.g. via social engineering), allow for lateral attacks resulting in much bigger impact (e.g. Lapsus$) across the complete customer base. This makes social engineering much more attractive in cost vs impact. The resulting mon…

> The difference is that cloud relies on public services What are the public services that AWS relies on, and how are they different from a bank's server farm, or a bank renting out space in a datacenter? The same, really, applies to all other concerns.

Route 53, CloudFront, AWS Console, AWS IAM, etc.

All of these services are hosted by AWS in a multi-tenant fashion, sharing not only the code, but infrastructure and configuration patterns.

Post reply on HN