Monzo’s Response to Cloudbleed
monzo.com
monzo.com
Love monzo. <3
Isn't the DDOS mitigation undermined by exposing the API used by your apps directly?
Seriously, CloudFlare is doing nothing new and nothing fancy.
They don't use cloudflare to MITM customer data.
"Did you even read the article? It mentions that" can be shortened to "The article mentions that."
One question - does anyone else feel that having NGINX as the only link in the summary kind of suggests that it's an nginx problem? I could imagine my previous boss reading the article, and 3 months later saying, "Wait what, we're using nginx??? Isn't that that shit that made cloudbleed happen?"
This caught my eye as well. Not sure what to do about it other than link/read the cloudflare blog post/incident report. FUD, etc.
BUT... The moment you passed your argument through a severe vulnerability related to NGINX (doesn't even have to be directly related, mind you!) will be disclosed and you're boss will jump-in screaming "I KNEW IT, NGINX IS BEHIND ALL THIS!" (he'll be spelling it correctly by then :-P )
Caddy can serve 5,000 requests per second per core. I would flip your statement on its head, and say that a minority of people need anything close to that. The few companies that do, can probably afford to keep on top of CVEs for their frontends as well.
Empty request benchmarks are indicative of nothing in the real world.
For any reasonable workload, even serving static sites of a few kilobytes they will be effectively the same.
Caddy's sane default settings (enforcing SSL, and with correct settings to get an A+ on SSL labs) make it the right choice for a lot of deployments
https://github.com/mholt/caddy/issues/1204#issuecomment-2781...
Greenfield writing a new safe reverse proxy that works within a magnitude of performance of something like nginx is a monumental effort. Not to mention the chicken-and-egg problem of how nobody will trust it until it has significant usage which it won't get until some people trust it.
Like an online banking app?
> "We've seen absolutely no evidence that this has been exploited," he told Reuters by phone.
> "It's very unlikely that someone has got this information."
http://www.reuters.com/article/us-cyber-cloudflare-idUSKBN16...More precise: a bug in a proprietary closed source module for NGINX used in-house at Cloudflare.
[1] https://bugs.chromium.org/p/project-zero/issues/detail?id=11...
They also offer good exchange rates with no fees.
Personally I use it as a travel/buffer card as my main card has been copied in the past and I usually have sub £100 on my Monzo card.
It is particularly useful overseas. I was in Belgium at the weekend and all my € spend was immediately translated into £ so I could clearly see how much I was spending. I could also find the café that I went to for breakfast the previous day because it's location is right there in the Monzo app.
The other useful feature is when I'm out drinking. If I loose the card, I can freeze the card from inside the app. Also it means that the next morning I can see how much I spent.
Damn I'm going to Europe at the weekend too, thought the 2% charge my bank does isn't so bad but I may have to finally get on the Monzo train.
If so, for those based in the states, you ought to check out Simple (https://www.simple.com) - it's great, it has a clean user interface, there are no fees, and the customer support team is top notch.
I assume it's the same thing (Simple and Monzo). Anyone know of any major differences between them?
The thing is, their big value add is the instant notifications. As far as I can tell from reading their blog, this took a lot of development effort: https://monzo.com/blog/2015/12/15/why-are-foreign-card-payme...
All of my regular financial accounts (bank, credit cards) can do this. There's typically a page in the account center with settings for sending SMS and email alerts when various types of transactions exceed a certain monetary threshold. I set them all to $0 and get notified of everything as it happens.
I think our banking system is a bit antiquated. Monzo have built a tech stack that is far more advanced than any of our incumbant banks.
Anecdotally, it seems Scots are more likely to say Scot* vs UK than are Welsh/English to offer the equivalent. I certainly grew up (in England) with the feeling that one had to be careful to say 'UK' if one really meant UK, for fear of similar reprimand to that when using a gendered pronoun that may or may not be correct.