Live data from Hacker News

How we secure Monzo's banking platform

monzo.com

61–70 of 148 posts

Re: How we secure Monzo's banking platform

#61
post #56
post #54

Earlier quoted context omitted.

> Sure, but that doesn't explain the sheer scale on which it happens How do you know the scale and how are you not sure that it's a vocal minority? After all, Monzo does target more tech-savvy users that might be more likely to voice their frustration online than with other high-street banks. > One gets the feeling they're hiding behind the "we can't tell you why" excuse to escape accountability for a broken system t…

> How do you know the scale and how are you not sure that it's a vocal minority? Read the articles and look for similar experiences for other banks. There's definitely a lot more noise about Monzo doing it. Maybe (as another comment suggested) there's a selection bias at work but I assure you it's a real thing, and appallingly handled by Monzo when it happens. > Because maybe they are being forced to hide behind that…

What's the average age of a Barclays or TSB user vs a Monzo user? According to this, 72% of Monzo customers are 18-35: https://www.businessofapps.com/data/monzo-statistics/

If that's the case, it's fairly obvious why there'd be a lot more noise - a lot larger percentage of people in that age group doing crypto, and a larger percentage are "very online" and likely to complain about it there.

Re: How we secure Monzo's banking platform

#62
post #44

Earlier quoted context omitted.

Sure, but that doesn't explain the sheer scale on which it happens (more than other UK banks and with seemingly worse consequences) or how the system actually works. It's also notable that this post was written a year before some of the news articles, indicating that Monzo really hadn't done anything to improve it. One gets the feeling they're hiding behind the "we can't tell you why" excuse to escape accountability…

They are 100% not behind the 'We cant tell you why'. It only takes the smallest amount of reading to figure that out. They have to report it to the FCA and you can read the reports from the FCA that suggest its not actually any worse than other banks. Its just more talked about. (No I am not going to dig them out for you).

Searched and I can't find any. I did, however, find a Which? article that says "Resolver found almost three-quarters of complaints about frozen bank accounts mentioned ‘digital’ banks".

Statistically it doesn't seem likely that Monzo and its ilk would be so overrepresented merely because their customers are more fazed than others about having their money taken away. Still, if the FCA have published meaningful statistics I could be proved wrong.

https://www.which.co.uk/news/2021/09/why-banks-are-freezing-...

Re: How we secure Monzo's banking platform

#63
post #49
post #46

Earlier quoted context omitted.

My money is on it being crypto related, but that’s because the only people I’ve seen complaining about this publicly were doing some crypto stuff (tx both in and out) and it looked very laundry-esque out of context when you get into the actual details And yeah as others have said that’s not a Monzo thing not telling you, no UK bank would tell you why they think you’re laundering money

Not in my case - no crypto, no recent large transfers. I'm a boring middle-aged IT consultant, not a terrorist, drug dealer or crypto trader. There was absolutely nothing I'd done with my account that should have caused this to happen. That's what's so kafkaesque (and frankly rather violating) about the experience: you literally haven't the faintest idea what you've done wrong and the bank refuses to tell you.

Yes the law compels them to be like this. It’s actually criminal to tip someone off they’re being investigated.

Perhaps the law is too strict due to the impact it can have on individuals.

Re: How we secure Monzo's banking platform

#64
post #58
post #49

Earlier quoted context omitted.

Not in my case - no crypto, no recent large transfers. I'm a boring middle-aged IT consultant, not a terrorist, drug dealer or crypto trader. There was absolutely nothing I'd done with my account that should have caused this to happen. That's what's so kafkaesque (and frankly rather violating) about the experience: you literally haven't the faintest idea what you've done wrong and the bank refuses to tell you.

Use First Direct. They're designed for boring middle-aged IT consultants. :)

Not disagreeing (First Direct has a far better reputation) but it's really a brand of HSBC. The irony of having to move to a bank suspected of funding [1] actual drug dealing/laundering/terrorism so my accounts won't get frozen over imaginary drugs/laundering/terrorism is somewhat amusing.

[1] https://www.thebureauinvestigates.com/stories/2021-07-28/mon... / https://www.forbes.com/sites/afontevecchia/2012/07/16/hsbc-h...

Re: How we secure Monzo's banking platform

#65
post #28

Disgruntled former Monzo customer here. Do they still have a haywire fraud detection system that randomly freezes innocent people's accounts? It's happened to countless users and the customer experience when they do it ("we refuse to tell you why" and in some cases holding onto their money for months) is a kafkaesque nightmare. https://www.vice.com/en/article/bvg7n3/monzo-freezing-closin... https://www.reddit.com/r/U…

Happy Monzo customer here with it as my primary account for the last 2 years. Haven’t had any issues, and neither have any of my friends. It’s the best possible banking experience imo. I’m happy they are proactive about suspicious activity.

Re: How we secure Monzo's banking platform

#66
post #28

Disgruntled former Monzo customer here. Do they still have a haywire fraud detection system that randomly freezes innocent people's accounts? It's happened to countless users and the customer experience when they do it ("we refuse to tell you why" and in some cases holding onto their money for months) is a kafkaesque nightmare. https://www.vice.com/en/article/bvg7n3/monzo-freezing-closin... https://www.reddit.com/r/U…

> Do they still have a haywire fraud detection system that randomly freezes innocent people's accounts? I

As others have pointed out already, AML/KYC laws are strict. They are strict in general for financial services, but for banks, because of their privileged position in the financial system, its even stricter.

But there is a second aspect which is that challenger banks such as Monzo take an even more cookie-cutter approach. If you don't fit their definition of what a "client" is then you will be in for a hard time. Normal banks do this too (to a degree) but challenger banks are much more hard-core about it because if you fall outside the cookie-cutter then you mess up their fragile business model.

Case in point, I know of a well-known, well-established, UK VoIP operator. They moved their business over to one of these challenger banks (might have been Monzo !) because the challenger bank provided APIs to enable integration to their internal systems, which is something that the old-school high-street bank did not offer - and the banking fees were lower too, always a bonus !

TL;DR: $challenger_bank had a definition of a client that did not include provision of VoIP services. So after about a year as a client, said VoIP provider found their account frozen (in this instance they were explicitly told, it wasn't a silent freeze). VoIP provider attempted to constructively engage with $challenger_bank but it was like talking to a brick wall "computer says no".

(N.B. I have oversimplified the story a bit, so please don't nitpick !)

Re: How we secure Monzo's banking platform

#67

Earlier quoted context omitted.

That's more or less the same question as "what if the data center/servers operated by the bank gets compromised". In reality it's always about tradeoffs: who to delegate to and who to trust.

>That's more or less the same question as "what if the data center/servers operated by the bank gets compromised". The difference is that cloud relies on public services, which once compromised (e.g. via social engineering), allow for lateral attacks resulting in much bigger impact (e.g. Lapsus$) across the complete customer base. This makes social engineering much more attractive in cost vs impact. The resulting mon…

> The difference is that cloud relies on public services

What are the public services that AWS relies on, and how are they different from a bank's server farm, or a bank renting out space in a datacenter?

The same, really, applies to all other concerns.

Re: How we secure Monzo's banking platform

#68
post #43

Earlier quoted context omitted.

Containers are really a kind of process-isolation - you still share a kernel. You can find a lot of people saying that containers aren’t enough for running untrusted user code. If you run a fully virtualised instance you get your own kernel and aren’t relying on process isolation. Would you be happy if your cloud provider was running your containers on the same virtual I stance as someone else’s? Most people wouldn’t…

The only meaningful difference between breaking out of a process-isolated "container" and a full-blown VM is what's waiting for you outside once you've broken out. Whether it's kernel/OS or a bare metal hypervisor isn't really all that meaningful: exploits and vulnerabilities exist for either. There should be proper hardware-level isolation here, depending on the scenario. Most cloud companies can't afford that thoug…

Genuinely, would you be happy with just container isolation between you and other customers of your cloud provider?

Most people absolutely would not.

Re: How we secure Monzo's banking platform

#69
post #22

Earlier quoted context omitted.

Exactly. containers are not secure sandboxes by default and if one is breached all those K8s networking ACLs are worthless.

> "Exactly. containers are not secure sandboxes by default and if one is breached all those K8s networking ACLs are worthless." Your suggestion being? Putting a sandbox inside a sandbox? How many layers deep should this be, before being considered "secure"?

Most serious security teams do not consider containers a security boundary. So it’s not a sandbox inside a sandbox, it’s just a sandbox.

Gvisor and firecracker are the most popular sandboxes for containerized workloads.

Re: How we secure Monzo's banking platform

#70
post #62

Earlier quoted context omitted.

They are 100% not behind the 'We cant tell you why'. It only takes the smallest amount of reading to figure that out. They have to report it to the FCA and you can read the reports from the FCA that suggest its not actually any worse than other banks. Its just more talked about. (No I am not going to dig them out for you).

Searched and I can't find any. I did, however, find a Which? article that says "Resolver found almost three-quarters of complaints about frozen bank accounts mentioned ‘digital’ banks". Statistically it doesn't seem likely that Monzo and its ilk would be so overrepresented merely because their customers are more fazed than others about having their money taken away. Still, if the FCA have published meaningful statist…

I can't tell which way the arrow of causality points, but all the digital banks in the UK are in various stages of still growing to reach the scale where they can become sustainably profitable.

This in turn means that they will have their risk assessments inverted from the usual high-street banks: optimise signup/account creation flow, and deal with AML requirements in a slightly delayed fashion. Making it really easy and smooth to open a current account brings in a surprising fraction of the crowd who would be rejected or otherwise earmarked by high-street banks.

Being digital upstarts, these modern banks also don't have the fraud and risk departments their established competition has. In order to not get hammered by the FCA, they almost certainly veer on the blunt instrument side when dealing with suspicious activity. And law of large numbers guarantees that there will be a significant number of false positives.

Post reply on HN