Live data from Hacker News

UK bank fined £49M over IT system meltdown

bbc.com

81–84 of 84 posts

Re: UK bank fined £49M over IT system meltdown

#81
post #72

Earlier quoted context omitted.

In many cases it can be though. If I'm asked for an estimate to do X and I say I can deliver in three weeks, and my boss says customer needs it for golive in three days, I'll try to find some way of making that work. Perhaps they can live without a full solution for the first few weeks, instead requiring only a subset of the requirements in that period. Or, if I insist it just cannot be done, I'll tell the boss who'l…

That's a discussion. Not haggling. Demanding the same for less is haggling. As if we can magic time reductions out of our asses without cutting features .

Fair enough, I interpreted it a bit differently.

Of course on any project I might be able to deliver the same in less time, but then at the expense of something else. That might be acceptable if the boss thinks he can manage the other clients which work gets delayed.

Re: UK bank fined £49M over IT system meltdown

#83
post #66

Earlier quoted context omitted.

+1 on the Yubikey. I'm pretty good at moving my savings around and getting the best interest rate possible - the side effect is a ton of accounts, which means I'm drowning in 'secure memorable passcode key PINs' and my SMS inbox is full of SMS 2FA codes, and I'm wondering what it would take to get a bank to offer Webauthn/FIDO. How about a website where we pledged to open an account and deposit £X into savings, or sw…

I'd love FIDO for online banking auth. But AIUI, there's some EU regulation that requires 2FA, but that 2FA must also verify some other data (like the recipient of a transfer, amount being transferred and suchlike). I don't remember the details, but unfortunately that rules out FIDO for 2FA to make transactions. For initial authentication it would work, but it would have to be yet another system on top of the 2FA the…

That makes sense, thanks for the info.

Re: UK bank fined £49M over IT system meltdown

#84
post #21

I have a bank account with TSB and got compensation as a result of this mix-up. Some rather personal experiences of the fiasco: – Rather pointlessly, the website changed from being mostly static to entirely written in a very JS-heavy, "dynamic" way. I still can't use it in my normal browser (FF) with its extensions because it relies heavily upon CORS requests and referrer information that my somewhat privacy-paranoid…

As a privacy-aware user, when making a contract with a bank (or buying a flight ticket or whatever) you should get assertions that their web site meets certain quality standards so you can use your browser to access the account or actually check in. Paper did not have those incompatibility problems... However, from the BBC article I conclude that even customers with a default browser could not necessarily use their a…

> you should get assertions

I think you’d get blank looks if you asked that question followed by generic we use modern blah and new improvement next blah

Post reply on HN