Why should he spend his time (=money) to chase down a multi-billion dollar company to get them to fix a stupid error when he'd be lucky to get a thank you email for the effort?
Two successes:
- I'd determined that a large email provider was transiting a sizeable fraction of all 419 spam I was seeing (and knew that this was likely broadly representative). Looked up the product title with "project manager" and similar terms, called the corporate switchboard, and asked for them by name. Phone picked up on first ring, I explained the situation briefly, fifteen minutes later I received a call from the manager in charge of that area, who leptnin touch over the next three months as the issue was resolved.
- Another time worksite had issues with another email service provider with glacially slow processing of our notification emails. Performed an executive email carpet bomb[1] after months of ineffective helpdesk attemps, with evidence of the issue. Was assigned a minder who helped resolve the issue.
Both were large companies (at the time), one I'm distinctly not inclined to consider favourably. Both responded exceeding expectations.
Then there is Google....
________________________________
Notes:
1. See https://www.nytimes.com/2017/05/05/your-money/the-best-consu...
>How about @BarclaysUK pay @internetarchive for bandwidth usage and make a donation to @BlackGirlsCode for good measure.
It's really annoying how people love to moan on Twitter without context.
I'd assume that for banks all code that goes into production gets audited. More so it is easy to have the code run through some analyzers before submitting it to production where presence of external origin should be detected automatically and raise a flag.
If not it is gross negligence on the bank's side and deserves all the scathing and accusations it can get.
Yes and you know who's then get fired? The junior developer....
Code would be reviewed by a developer, not audited. The reviewer may or may notice the dependency to archive.org and may or may not care.
Speaking from experience, the bank may have a policy to prohibit using external javascript, while the bank may not have a CDN itself to be able to host said dependencies.
The point of tag managers is to let non-developers update production without going through a code deployment so the usual code review and oversight doesn't apply.
Also worth keeping in mind that this is the bank's marketing site. It's almost surely managed by a different team than the actual online banking site and probably has looser restrictions.
When I was in high school in the 90s I did work at a bank after school. My job was to sort and file debit card applications. No one audited my work either. Part of my job when reviewing every card on file was to verify the balance on the account that backed the debit card. If the account balance was zero or less, I filled out a form to cancel the card to be faxed out in a batch. Typically had 20-50 cancellations per day in 3 hours of work. No one reviewed them before sent, the files were just filed away to be forgotten. Mind, this was a small rural bank, so that might have played into it.
Either scenario is equally bad when it's a multi-billion dollar financial institution. It's a bank not some Wordpress site for local business.