"Unless you're reading every line of code"
Not only reading but understanding. That's the tricky bit.
42273 publicly visible posts • joined 16 Jun 2014
"in principle it's a great idea"
The reason it's not in practice is that the banks have spent years in a race to the bottom. Now consider what happens if customers regularly move accounts in response to bad service. All it would be one bank to realise that if they made serious efforts to improve service they'd gradually capture the market. Eventually the other banks would catch on & there would be a race to the top.
As customers we can't directly impart that realisation to a bank but by keeping that churn going we can present the opportunity.
"There are still cases in rural areas where users can only get dial up access, given these customers are less likely to have access to a 'branch' and more dependent on online service"
This is First Direct. Online & telephone is what it does.
"It has little to do with IT competence and more to do with effective customer communication."
And what this communication tells me speaks volumes about its approach to customers. It might be misinformation but its the information it provides and that's what you need to rely on.
There's a back-story to this. I used to be a Midland group customer for about 40 years and happy to be so despite the fact that as HSBC their business banking group couldn't get their heads round the fact that if they wanted to ring me up they needed to prove that they were who they said rather than demanding I prove who I was before starting their sales pitch... I digress.
Two things went wrong eventually. One was that they closed the branch at which I preferred to do business. The other, which is more relevant here, there was a little problem with the credit card payment system. Paying off a credit card appeared to be a duct-tape job. I'm pretty sure it handed over from one system to another half way through. One night, fairly late on, trying to find a time when systems might not be busy, I tried to pay off the card & the hand-over failed; I got an empty document message on the browser. So I decided, as one sysadmin to another, to give them a friendly heads-up that they might have a problem. They wanted to know the S/W I was using. I got a very snotty reply that they didn't support my combination of OS & browser - which had worked perfectly, which I was quite happy to support and which was nothing to do with the problem they had which I was trying to tip them off about (& may well have been an overnight run slowing down the response). This was eventually confirmed by letter & in due course I went elsewhere. Before I switched I checked on other banks, asking where there wasn't a statement online, and no other bank I looked at seemed to give a toss about customer's OS.
After a couple more banks have closed their more convenient branches it's now more or less a level playing field from that point of view so I decided to give HSBC in the form of FD another go. Based on that previous experience, and knowing that in the past the FD website had stated the same policy, I checked first. Their S/W requirements have changed in the interim but that LAN statement has now appeared. I'm awaiting clarification because from that experience I wouldn't put it past them to use the fact that I'm not on a serial link to a dial-up modem to wriggle out of any problem.
"Migrating large amounts of data can be a pig, but our DBAs are more than up to the task if they're given sufficient notice to prepare"
I can testify to that. I've spent a few weekends doing that when the client's vendor released updates. As the site was warehousing it meant having the business clear a weekend so it needs more than simply IT planning.
Fortunately it didn't happen too often and, after all, it was billable ;)
"they are an IT house which does banking."
Sadly, not true. That's what they ought to be. It's what all banks ought to be. But are any of them? For an example of a bank's IT competence take this example from First Direct's page of what you need for internet banking:
modem (minimum speed 56kbp).
Please note: PCs and Macs connected to Local Area Networks are not supported.
Nobody told them that these days home users' PCs & Macs are normally connected to the net by ADSL or FTTC via wired or wireless LAN.
"NoSQL being used where RDBMS are more appropriate"
I'm beginning to suspect this is because of modern development methodologies. Don't bother to work out what you need, just dick with it till it's right, fix it in the next sprint & all that.
You can do that with code, no problem, but once a database is deployed & populated it becomes a pig to have to reorg large amounts of data. Cue DBAs taking the cattle-prod to the devs.
If you're going to use RDBMS you have to design (shock horror!) first so that what goes out into production can stay there with as few changes as possible for as long as possible.
"I'm leaning towards "This is BS", but absent any evidence either way, I just don't know."
Let me help a little.
Let's assume it's true that the files have been decrypted by the Russians, Chinese or whoever (RCow). Presumably this would mean that they'd discovered an intentional or deliberate back door in a supposedly solid cryptographic system. This raises a question: how would the UK or US know?
Possibly RCow took some action that revealed it. But remember that decrypting German cyphers in WWII was so sensitive that it was kept secret for decades afterwards. It was also so sensitive that not all information could be acted on & a disinformation operation was run to provide plausible alternative sources. Would RCow be so incompetent as to let slip, by incautious word or deed, what they'd accomplished. It strains credibility.
Alternatively perhaps the western cryptographers decrypted a message by RCow saying that they'd achieved this. The same reasoning applies. Would they then release this story and reveal what they'd accomplished?
I call BS.
"most of it is public information"
So it is but for any one person it takes time, effort & expense to locate as anyone interested in genealogy will tell you. You may run into multiple people with the same names and have to devote more time to sorting them out. Having it all neatly laid out by the data subject saves an awful lot.
"This is entirely different situation as we are not enemies with ourselves."
There is, in fact, a similarity. If my govt. wishes to spy on me it should do so with due process of law. It should go to a judge, or at least a magistrate, with sufficient a priori evidence to get a warrant. This concept of due process was introduced into English law by Magna Carta. In a few days, no doubt, the PM will be saying how great Magna Carta is & how splendid that this has been part of English law for the last 800 years - whilst being quite happy to see this principle violated.
An APT can't be expected to use due process. My govt. should. It is unacceptable if, like the APT, they don't.
"Nobody does spot checks on checksums for data that shouldn't be changing?"
That doesn't help with data that should be changing. Nor does it help with whatever the original vector was - that won't have changed and will still be a potential danger.
I'm not saying you're wrong to say flatten & rebuild as that's my view as well. But transferring the data cleanly to a new build isn't going to be easy as it will all need to be vetted.
And whilst this is happening business needs to continue. A long time ago someone described a particular migration as like transferring passengers from one aircraft to another in mid flight without waking them up. This sounds like another of those.
Where's the experiment? All you say is that there's a lot of Linux about. No experiment, thought or otherwise
And then you trip up by the comment about BSD being like Linux. You've got the resemblances in the wrong order. BSD is a Unix variant. Linux is a Unix-like OS - and one that's rapidly becoming less Unix-like in the estimation of many of us.
"It is still somewhat parochial, especially to those of us who are, thankfully, not within the gravitational field of the blackhole that is LUN DON."
I take it you're not a UK taxpayer. Because for those of us who are our money is definitely within the gravitational field.
"The thing is, no user cares, any more, what the underlying O/S is. They do care about the quality, range and ease of use of the applications they want to run.
And this is where Linux still falls down, flat on its face. "
I have a cousin-in-law who could be the archetypal uninformed user. For several years I had to go round to run his annual Sophos licence update before he had confidence to do it himself. I bumped into him in the street the other day & he asked me to call round & install Linux for him. He has an old Dell that's on XP. All he needs is a browser & I can install a choice of those for him. And a whole lot more he's probably never thought of but it's going to confuse him no end not having an A/V package.
"They're MEP's pretty much the most fairly elected and representative politician we'll ever encounter."
Powerless. You forgot powerless. The European Parliament is a fairly powerless talking shop.
It's the officials who have the power. They're appointed. We're not allowed to vote for them.
The powers given to the officials are given by treaties. We're not often allowed to vote on the treaties. When people have been allowed to vote & voted No they've been told to vote again until they gave the right answer.
So perhaps the disenchantment in Britain stems from the fact that we're not allowed to engage in any democratically meaningful way.
"Make it mandatory for all software licences to be registered centrally, and forbid unauthorised staff members from signing licences or contracts."
If there are no consequences for ignoring such mandates people will do so. Get the bean-counters to agree that any dept. the drops the business in it by breaking licensing rules will have any penalties that the vendors impose charged against them. If nothing else it will protect the IT budget.
I worked in a building that had Big Red Buttons (standard Radiospares product) at intervals along the corridors. They sounded the bomb alert. One day the alarm went off several times with consequent disruption. It was eventually traced to one of the cleaners who decided the the buttons needed polishing.
I spent over a decade dealing with terrorism amongst other crimes. My place of work was car-bombed. I survived handling an item that turned out to have been booby-trapped with explosives. So when I tell you that I think due process of law and presumption of innocence are right and unconstrained trawling wrong I think my arse is reasonably well informed. And yours?
"the Register's position on this topic"
It's news to me that the Register has a position. It publishes articles by individual writers.
"I really wish El Reg would just stay away from this topic altogether."
OTOH, if you're not happy with it you could stay away.
"to the embarrassment of everybody else that works there."
Citation needed. Has anyone who works there told you they're embarrassed? AFAICT they must be a fairly unembarrassable lot.