Live data from Hacker News

Tolerating full cloud outages with Monzo Stand-in

monzo.com

41–45 of 45 posts

Re: Tolerating full cloud outages with Monzo Stand-in

#41
post #37
post #26

Earlier quoted context omitted.

I've heard that one before

I mean, it's been in production for years, has a cap of £20k and I'm pretty sure the design of BACS means it's very difficult to recall a transaction after the 4pm time when the feature becomes available. Simon is probably in a very good position to know how often that sort of thing happened, if ever. I'm pretty happy with them offering this based on my understanding of BACS, as a shareholder.

20k... per account? adds up

I suppose most people won't have 20k (net) payslips, or draw it all out on pay day!

I'm not saying he's wrong, but covering a risk of this nature? I'm sure you'd be able to find someone to take your premiums

whether you'd be able to collect on it when needed, in the situation where the financial system is under serious stress is something else (see: 2008)

Re: Tolerating full cloud outages with Monzo Stand-in

#43
post #7

A decent setup which allows you to prove you are not dependent on 1 cloud provider will probably pay for itself when it's time to negotiate discounts.

I doubt the sales folks you'll be talking to will care about your multi cloud deployment, as they don't have the skills to verify something like that.

Well you can turn them off for a day and they have the skills to see that.

Re: Tolerating full cloud outages with Monzo Stand-in

#44
post #24

Really interesting. Would love to understand how they came to the decision to build this,and whether there's any precedent for it.

Part of being a regulated bank in the UK is proving infrastructure resiliency.

Monzo were the first bank here to run entirely on the cloud, so I imagine the regulators were extra strict with them.

I'm not saying this level of resilience is due to that alone, but perhaps it started them on the path?

Re: Tolerating full cloud outages with Monzo Stand-in

#45

What I wonder is “have they isolated third party dependencies?” If AWS is hard down, those may well be impacted—in some cases, by their own third party dependencies. You can test turning off your AWS environment, but you can’t really test turning off S3 for everyone…

It's a very good question. The stand-in system itself has been built to have basically no external dependencies itself.

So, the question you are really asking is "to what extent are the other parties involved in the processing of payments resilient to AWS failure" – e.g. Stripe probably isn't and that's probably a decent chunk of e-commerce.

I definitely don't think this would be anything close to smooth sailing if AWS was to fully go down, but we do have the benefit that underlying payment infra is still dominated by on-prem with leased lines etc. My best guess of the actual behaviour would be that bank transfers would keep working, the card networks themselves would keep working but the average e-commerce website would not.

Naturally, we can only control for what we can control for – and for us the primary benefit of stand-in is what it gives us in the much more likely scenario of an incident in our platform.

Post reply on HN