HNHacker News
TopNewBestAskShowJobs

throwaway201606

214 karma · joined July 5, 2016

submissionscomments
throwaway201606··on Substack won't make you rich
The "curation is an great addition to value" argument is certainly a powerful one.

I agree with the position that it makes sense to pay for a selection of writing (or other content) that someone, who truly deeply understands their demographic, puts together.

This site ( HN ) is certainly proof of that. It is effectively a magazine curated by its readers (upvotes/downvotes) for 'my deomographic' which is the demographic of everyone on here I guess.

In the novel "Fall", Neal Stephenson developed a theme I found profoundly insightful - the internet becomes a morass of trash so to get anything out of it, you gotta be selective about what you read or consume.

Selectivity, for characters in the book, was effected by subscribing to 'edit streams' - content pushed to them by editors who figured out what they should see for news and what they should see elsewhere from the arts, science, anything.

The super wealthy have personal editors - bespoke curated balanced content that was super expensive since one essentially is paying for person to "pre-read" and "grade" everything.

The 'middle class’ subscribes to one or more cheaper good shared 'edit streams' that had balanced and nuanced selection made possible by amortizing the cost over a ton of subscribers - a magazine.

Everyone else consumes what FAANG equivalents and bottom of the barrel anybodies pushes out for free on the "Your Feed" streams. Since they are free, you are the product.

Anything on those is largely driven by agenda - think "the right vs the left", propaganda, 'just because I have a mic", anarchy, pick your poison.

Two thoughts pop to mind out of all this

- just occurred to me that Facebook's / TikTok's /YouTube's etc "For You" streams are just really bad, (very addictive) very poorly edited magazines. Can't really make money from them because they are the equivalent of a old-timey pulp magazine.

- (this is the biggie) these FAANGs should set up some way for folks to make money through curation of their content (patented, TM, etc). Just send me a cash "Thank You" to cover college bills and the mortgage for this idea.

throwaway201606··on Databases and why their complexity is now unnecessary
Amen

To me, this looks like an example of those ads that look like this

edit ( tried to do a text table right on here but it got really messed up in the page display)

here is a screenshot of the effort

https://imgur.com/a/XtwSkyx

throwaway201606··on The Case of a Curious SQL Query
100% this: part of this crew.

I have, over the course of my career, found that the teams that tend to do this are pure-SQL teams ie in DB developers who spend all their time writing - and more importantly - reading SQL. Doing this actually removes a lot of debugging and code-fixing friction

throwaway201606··on Credit Card Debt Collection
The real issue is reputation risk.

Banks do not want to be in the news because they put someone on the street because of $100 or $500 or $1000 - the reputation cost is just too high.

Further, most banks will not sell debt under a certain amount., they plan for the losses, adjust for it in lending rates and just write off the debt as a loss.

You will see this in their annual statements as provision for credit loss (the planned losses) and net credit losses (actual losses). The amount for large banks is in the hundreds of millions and it is taken as part of the cost of being in the lending business.

There is, of course, some every fluctuating number based on the type of lending and amount, at which debt is pursued with vigor.

throwaway201606··on I'm OK, the bull is dead (2004)
OK, finally found the key words that let Google point me to the comment with Mr. Kapur's response giving a fuller explanation of what happened.

https://www.computerworld.com/article/2567290/no-more-bull.a...

throwaway201606··on I'm OK, the bull is dead (2004)
Jumping in here since this has floated to to the top and I responded to a similar comment below.

Felt strongly enough about this that I actually took the time up write an actual literal paper letter (or maybe an email, don't remember... but paper letter , stamp, walk 20 miles uphill to post office works better for dramatic effect ) back in 2004 to ask the question.

The question was asked in the magazine and the answer by Mr. Kapur was published in the magazine.... but my google-fu cannot find the answer he had posted back then...

Unfortunately, I don't remember the answer so the cliffhanger continues.

https://www.computerworld.com/article/2567061/no-bull-approa...

throwaway201606··on I'm OK, the bull is dead (2004)
felt strongly enough about this that I sent them an actual literal paper letter (or maybe an email, don't remember....) back in 2004 to ask the question.

The question was asked in the magazine and the answer by Mr. Kapur was published in the magazine.... but my google-fu cannot find the answer he had posted back then...

Unfortunately, I don't remember the answer so the cliffhanger continues.

https://www.computerworld.com/article/2567061/no-bull-approa...

throwaway201606··on Google’s Plan to DRM the Web Goes Against Everything Google Once Stood For
All can be fully viable, very profitable, very large independent businesses.

Android Based on information obtained by Oracle in a lawsuit, Android had, as of 2010-ish, generated $31bn for google

https://www.androidauthority.com/android-generated-google-31...

Chrome: Browsers make money by

- sharing revenue from ( product and service ) ad searches

- prioritization in search engine results in the browser ( eg being set up as the default search engine)

https://www.investopedia.com/articles/investing/041315/how-m...

It is estimated, for instance, that as of 2021, Google was paying Apple $15bn for default browser placement

https://www.theregister.com/2023/02/17/google_apple_chrome_i...

Google Analytics:

This is much harder to research - since looking for 'revenue' with 'Google Analytics' simply shows how to use the tool to track revenue for 'your' site if you are a Google Analytics user and my Google-fu fails at a quick remedy for that.

Best quick result would be a proxy i.e. competitor revenue. MixPanel is a standalone Google Analytics competitor and it makes $96MM from that business

https://www.crunchbase.com/organization/mixpanel

throwaway201606··on Use databases without putting domain logic in them
Tom Kyte, who for a long time was the "ambassador to the world" for Oracle, makes essentially the same arguments

https://asktom.oracle.com/pls/apex/f?p=100:11:0::::P11_QUEST...

For data that will either :

+ 'outlive' the user interface - this data will be used forever but we are not sure where e.g. financial docs, records, etc etc

+ 'extend' past the user interface: this data started on an installed desktop app / green screen but we are not sure how we may want to extend it - eg to an API or to web

the DB is the right place to put business logic.

Coupling the data with business logic, in the DB, allows almost complete flexibility in how it is access and interacted with at the expense of complete lock in to the DB platform. Which may or may not be a bad thing. But if you have a skilled SQL team and some resources to pay the DB licensing and support piper, this is a good direction to ensure app support longevity.

For example, you can do the same thing on desktop or phone or web client or even hardware switches: say you have a DB stored_procedure to indicate that the process of manufacturing this part has reached stage X

update_item_status( Item 11111, 'Manufacturing Stage X' )

(these is obviously really contrived but it is an example to make things clear)

You can run this, if it is in the DB by:

- hitting this button on the assembly line

- scanning a barcode can do the same thing

- having a user change a status in a UI

- have a batch job run off a script with a list of parts to apply the status to

And even better, if you want to update how the stored proc works, you update once in the DB and it is available to all 'interfaces' instead of having to update hardware switch code + user screen UI code + batch script code etc etc...

I know that an argument can be made that you have an app server layer separate from the DB so this is not a 'real' problem but this approach just puts the app server IN the DB

One closing thought: it is often easy to forget that, in most cases, the data is the product of software development and the tooling is just support. Only counterpoints I can think of here are games and interactive demo systems where the process ( of playing the game or using the software ) is the product.

Positioning the database and front-end as being similar is a mistake if business goals are thought about from a "the data is the product" perspective. If the rules about how to handle, manage and interpret the data are a core component of that data product, then the argument that the right place for business logic is in the DB is made even stronger.

throwaway201606··on ChatGPT and Wolfram Is Insane
Stephen Wolfram actually wrote a fantastic piece in January about what Wolfram Alpha how it can be used to bring factual / analytical capability to ChatGPT

https://writings.stephenwolfram.com/2023/01/wolframalpha-as-...

Yesterday, the link between ChatGPT and Wolfram Alpha was set up (announcement was March 23rd 2023 ) which was probably the driver for the reddit post - a user trying out the new capability.

https://writings.stephenwolfram.com/2023/03/chatgpt-gets-its...

A bit of side commentary: I actually see these new AI tools as key facilitation tools in the next step into the world that Neal Stephenson envisions in the Book "Fall": a future that is a full-on information dystopia where the quality of your information filtering capabilities determines the quality of information you see.... because the internet and associated information sources are completely filled of with information that is just so slightly, but intentionally, wrong or off.

throwaway201606··on Most data work seems fundamentally worthless
This is a really good answer

i would also like to add that modelling in credit risk is not just about yes / no answers around loan outcomes.

There are lots of other goals that are regularly modelled such as default rates, profit optimization, loss minimization, delinquency and payoff rates at specific parameters ... endless options

There are also lot of different ways in which these models are implemented ( decision trees, statistical analysis, ML... )

Some examples of (real life) projects include:

- if our institution offers this card to clients with 750 credit scores vs 790 credit scores, how does my profit move vs my losses and what the factors to limit losses while maximizing profits

- how do I minimize my costs for servicing this card while keeping profits at the max ?

- what rewards options lead to the highest number of preselected / qualifying clients taking up a product at the lowest cost

- what contact strategies are best for specific types of clients if they are late on payments - call or email or text or legal letter? which strategies are the cheapest? which strategies give what this institution considers to be the best response ? which lead to fastest full payment? fastest partial payment? which lead to getting back to a regular payment plan?

- how can we identify clients who have a lending product with us who might be on the market for another lending product in the next 12 months? in the 6 months?, those who might need a limit increase pro-actively? those who whose might need a limit decrease pro-actively?

And, one of the largest area pf credit risk evaluation is real time decisioning on transactions: 'is throwaway201606 really buying $6000 of apple products, in person, at this mall in Toronto, Canada right now when I (the system) know I he bought a daily Wendy's Spicy chicken sandwich 10 minutes ago in Dallas" and should we allow this payment

Some example of how models are used here include ( note that modelling helps establish which transactions to look at more carefully and which to ban outright among other things )

- predict what type of terminals are being targeted: scammers -> we have left bank ATM machines alone and started looked at gas pumps:

- predict where transactions of interest might come from: scammers -> we do scams on site A at Christmas, scams on site B in the summer or we do site A scams with brand Y card and do site B scams with brand Z card

- predict behaviour patterns of transactions of interest: we always test the cards we will use by purchasing a $5 'brand x' gift card online 10 minutes before

throwaway201606··on Ask HN: Why are employees in technical roles in financial services discounted?
This is an interesting thread

TL;DR:

My primary goal in writing this is to connect with the audience of hiring managers who receive applications from candidates at banks

My goal is to convince you that 1 bit of info - that a resume is from a candidate at a bank - is not enough information to make viable assessments about the quality of the candidate. There is more info hidden behind that bit if you dig.

This additional info is based on the position that large FIs are so big that you cannot characterize developers working in them in any generic way.

The rest of the post is mostly a pyramid-style case-build in a wall-of-text making this case.

Net point I want to make is that there is no one global characterization of developer capabilities for folks in a large FI / bank that holds true to any extent. You have to know more by understanding where in the bank they worked, the technical environment they were in and what type of work they did.

Long Version

I want to offer evidence: from fact but somewhat anecdotal because the one 1 bank I know lots about != all banks ...

Warning - this is a long post and is a bit all over the place because I wrote it fast to get it out before the post gets too old. I also tried to be as generic as possible in my arguments so that they align with most FIs as much as possible. Please bear with my generalizations for those reasons

I am 'developer' who has worked in FANG, government, startups, healthcare, big-4 type consulting and other roles: currently at a 50k+ person bank in a hands-on tech/dev leadership role

First some context:

Banks, especially the big ones, are actually so big that they cannot be characterized as one company from both management and tech perspective.

It is better to think of them as a conglomerate of independent companies.

The org structure actually reflects this: you will find leaders who are responsible for everything, including P&L, for an entire group of say 1k-5k people (out of a total 100k employees) 1, 2 or even 3 levels down the overall org chain. These leaders will will have a title that, literally, says CEO of $X Business at $Y Bank. They are actually running fully independent business under the larger FI umbrella.

Look at HSBC here for example and note how many leaders there are with CEO titles https://www.hsbc.com/who-we-are/leadership-and-governance/se...

**

Most relevant for this thread - this operating structure means tech decisions are made independently, for each internally group, at the P&L business unit level, not at top of house.

Saying this a different way - there are no bank-wide decisions for production tech choices. There are only P&L group-level tech decisions. Full responsibility for P&L means full responsibility for choosing where and what to spend tech money, among all other monies, on.

The only top of house decisions would be around integration, data exposure and reporting tools. Never ever ever banking process production and production-support systems.

**

A by product of this is that moving orgs within the bank is literally like moving companies. You go to a new office, have new colleagues, with a different culture, working with different tools, on an entirely different tech stack

You might also likely, as a tech person, never interact with group you were in before. Different HR, legal and tech support folks, different leaders, different colleagues, literally like starting at a new company

With the the context above, the net of things is that, depending on where you are in the org, you could be in:

- a part of the financial institution that behaves like a startup, with startup incentives, management and results

(examples could be digital only banking, innovation groups etc etc)

- a part of the financial institution that behaves like how banks are traditionally characterized

(examples could be core banking platforms and systems dev., relationship banking groups eg private or commercial banking )

- a part of the FI that is stuck doing development work based on tech decisions being made elsewhere

(examples could be integration teams, reporting team etc etc)

- a part of the FI that is mission critical and everyone is loath to change - think platforms that NO ONE wants to touch because they JUST WORK and have been working forever and would cost the earth to touch!!

( examples could be mission critical production user facing or batch green screen COBOL/FORTRAN environments on mainframe - this is where the real big $s are, with FANG-type pay for folks with platform and environment specific experience )

I have also found that there are no internal prod tools that run across the org. All tools that are org-global are, by definition, reporting, aggregation or integration tools - taking info from some combo of tools and displaying it / sending it on to another set of tools.

This is the reason why $bn products and companies selling message buses platforms and green screen scrapers exist (TIBCO et. al) and make billions of dollars a year - these companies provide tools and products to connect independent systems (and thus businesses ) in the environment I described above, at scale.

I have worked on maybe 3 of the 4 environments I have described above at the bank where I am now and have found that the spectrum of skills, experience and tools across these orgs runs the entire spectrum of software dev. experience/ skills and needs/capability. The key driver, as with any other business is return on investment

Examples of the spectrum include:

- true, in production, internally built ML platforms for scoring stuff in real time (think card transactions flagging) that are probably close to best in class, that save hundreds of millions in losses annually run by true data scientist Phds

- access DBs to manage some proceed or fill some need with zero return ( eg compliance doc tracking) run by a gal/guy with zero programming/dev training

- completely home-grown self serve platforms with security & data segmentation built in serving groups with 3k+ individual users (which is a lot for a in-house corp tool ) run by the type of small scrappy team you would find at a typical startup

throwaway201606··on Stripe Identity
Actually, it seems that this did go into production - you can now verify identity using the service. For example, you can identify yourself for Govt. of Canada services (immigration, taxes) by logging into to your banking platform that then vouches for your identity using a service called SecureKeyConcierge / Verified.Me - note that ALL of Canada's major and quite a few minor banks are signed up to the service.

See this page:

https://services.securekeyconcierge.com/cbs/saml/login?l=1&l...

The way the service works by getting permission from you, the user, to share some part of your identity with the destination and you can chose what you share. You could pick for example just to share name and not DoB.

The one reason I hate this otherwise superbly designed service and refused to use it is that is has a dark pattern where it creates a "SecureKey / Verified.Me Concierge Account" for "you" when you use it and starts proxying/pre-emptying the bank-login-as-verification process.

WHICH IS STUPID AND SCAMMY IF YOU ARE READING THIS VERIFIED.ME, THIS IS DARK PATTERN BEHAVIOR AND IT IS NOT RIGHT OR FAIR

/start rant

From my perspective, the whole point is - inhale - "I sorta trust my bank because I have to so I will log on to them so that they can vouch for me but I definitely don't trust you so why are you being a dick and making me make an account with your service that I don't trust and will never trust" - exhale

Just let the bank vouch for me each time, this is what I expect a reasonable and non-scammy service provider to do. Don't wait till you have my info then tell me, hey, I will make an verified.met / secureconcierge account for you so that <insert your preferred monetization rationale here> before you do what you promised to do.

I get the idea that they want to consolidate a profile so that you can pick what to share without entering it each time but they way it is done right now feels really slimy.

/end rant

throwaway201606··on France cuts two nuclear-powered submarines in half to make one new one
The ship is a luxury cruise liner: the article, somewhere close to the bottom, says "Pricing for the 7-day cruise starts at $5,600 per person"

that 'starts" in the last part is kinda-important ... I took a look and they have 1 week cruises for $22,000

So, its really more like

34 more suites * 2 people * $5600 per person per cruise week = $380,000 more per trip at the low end

34 more suites * 2 people * $22000 per person per cruise week which is just over $1.4M more per trip at the high end

Assuming $15M from the 450k man-hours and $23M in materials for the retro-fit, (seriously over-estimating materials because I want the nice easy math that goes with a $38M total), it would be:

- 100 cruise-weeks or about 2 years to re-coup at the low end

- ~30 cruises (not cruise weeks, literally cruises ) to re-coup at the high end

throwaway201606··on Tensions in Google's ethical AI group increase as it sends demands to CEO
> What do companies stand to gain from hiring ethics researchers who are a liability to the shareholders?

Trying to tackle both questions at once: this is a viable trend and companies do stand to gain.

If the market is saying that you have to consider other motivations and goals aside from profits and growth, and you have built this machine that is super-efficient and effective at delivering on growth and profits irrespective of all else, you need outside skills to change.

To give a specific example, take the Norway Sovereign Fund which is one of the biggest investors in the world: it has indicated that it is incorporating environmental, social and corporate governance (ESG) issues into their decision-making,

So, if you want to get their investment, you have to have these goals in the your corp. leadership and performance management mandate.

To enable this, you need folks with these skills, who currently are not management, in the fold ( meaning folks like social scientists, ethicists etc. having really significant corp leadership roles and authority ).

throwaway201606··on Tensions in Google's ethical AI group increase as it sends demands to CEO
That idea that activists (in corp) don't constitute a tribe in an interesting opinion - one that I actually sorta-subscribe to.

I frame it in terms of acculturation vs. assimilation. You have to decide what your corp. policy is and make it explicit, something that I think did not happen here.

The conversation is something like 'if you join us, you do your thing BUT our way" or "if you join us, you do your thing YOUR way". Then folks coming in understand the ground rules.

I would say most corps will prefer option 1 but some (most?) folks coming in for roles like "Ethics" expect option 2 - which is NOT unreasonable. I don't know that this conversation happened (explicitly enough) here.

All of that aside, like I said in the parent comment, it is critical to consider that no one side gets to frame the position alone in situations like this where the job is literally, to come in and shake up status quo - everyone with a seat at the table has a say that should have equal-ish weight.

Also, note, corp in this specific case thought that that they are enough of a "tribe" to bring them inside the fence with a 'unique' label that makes that 'tribe' explicit. Witness what is going on here.

Labelling them as "spoiled kids" is "the missing part of the point" I was alluding to.

These folks have a different way of doing things. In bringing them in, you don't get to force them to align to your vision of how to do things (not what to do which you get to define as the employer). This is because you brought them in specifically and explicitly because they were different and bringing something different to the table that you did not have before.

If it was a set of skills, capabilities - whatever - that you could have grown in-house, you would have done so.

If you think that a 'tribe' can contribute value, you have to be able to deal with the pieces of their being 'different' from you that rub you the wrong way without labelling them if it is a key component of their identity.

More explicitly, don't blame ethicists for reacting in ways you don't expect to ethical issues.

throwaway201606··on Tensions in Google's ethical AI group increase as it sends demands to CEO
I wish I had more upvotes to give for this comment.

It gave me multiple upsights about how to clean up my approach thinking about the issues here:

+ framing an analogy using technology governance functions - whose functions and values can be clearly quantified and measured by many independently - with a ethical (moral) functions - whose values and results are much more nebulous

+ drawing a parallel between hackers - whom many technologists 'understand'- and value activists - whom many technologists don't 'understand

+ pointing out the now-self-evident axioms that i) activists, like hackers, hold you to 'their' standard, not yours and ii) will fight you 'their' way when you fail to meet those standards

+ the point about academia and corporate leaders needing to act as deans and dealing with navigating conflict resolution in a new 'tribe' they don't understand. Not forgetting they currently deal with multiple other tribes - investors, media, government etc.

I would like to add a couple of small points:

+ Personal risk to executives is the change in the mix with highest impact. This becomes more important as this risk is transferred up the corporate ladder.

So, leaders examining issues, from this 'new' perspective, in a balanced nuanced way while still considering profits, politics, strategy, foresight, ability to manage change ( et al, ad nauseam ) increasingly becomes a key career soft skill. Especially if decisions are delivered in communication styles that are still clearly understood by all relevant other tribes they deal with in situations like this.

+. I would like to suggest that some folks are missing PART of the point (not all of it, just an important small nuance) No single party gets to frame this debate. Ethics is now inside the corp. fence so it has to be heard.

Just consider that every side of the debate has their perspective and the other side is "crazy" from this viewpoint. E.g a key tool for academics with leadership is demanding the removal of leaders with a "or we go " chaser - this is normal in that world and it would be crazy not to use the tool as part of a "normal" negotiation. But it is not normal in the corporate world.

Point being everyone's normal is some version of some other person's crazy.

Well, these folks are from another 'tribe". The way things are done in their world is different'. Corp is the one behaving in a way that "does not make sense" from their perspective.

Just considering that the view from someone else's vantage point could be different would go a long way here.

throwaway201606··on Lessons from Dave Chappelle
[ edited to address a ton of grammatical and formatting mistakes ]

Lots of comments about how Dave Chapelle presents his position and the context in which he presents his position. The emotion quality of it all.

The is very little commentary about the core message of his rant - and Ben's comments.

Truth told, it should not be surprising.

The issues at hand are emotional ones about morals, justice and doing the right thing.

They are difficult issue to tackle and require taking subjective positions.

They do not lend themselves to a logical, intellectual and quantitative data-driven dissection.

He does however makes an excellent point from moral, social and justice-based perspective. He is holding media distribution companies at-large to account, and he is doing it from a qualitative perspective.

I suspect we will see more and more of this happening in the corporate world.

Whether companies have, or will acquire, the capacity and fortitude to tackle these issues is now up to them. The idea that profit cannot be the primary and only motive. Those that do will likely find it a rewarding approach in the long run.

What Dave is doing here is linking 'qualitative' issues to 'quantitative' results (money) in a very specific and effective way by, in his words "getting between a man and his paper".

throwaway201606··on Biden wins White House, vowing new direction for divided U.S.
Posting this, not to be confrontational but to share info.

https://twitter.com/FareedZakaria/status/1326255584069513220

This is a piece on GPS ( a CNN show ) where Fareed Zakaria lays out a potential election endgame, predicated on legal strategy with "allegations" as a key component, that seems to line up with exactly what is happening now. that could be very effective at altering election results.

Note that the video was recorded before the election and shows a potential strategy that uses legal challenges to voting results at various levels as a navigation tool aimed at ending with a situation where congress/states elect the president on a one-vote per state basis.

throwaway201606··on How We Justified Piling Debt on Poor Customers
So, you leave me conflicted..

... on the one hand, I want to yell "Strawman!" "Strawman!" "Come out and see the Strawman!" from the hills but I do not want to come off as aggressive or preaching ...

The point you make here is certainly true but it is neither the point of my argument or the point of the author's piece.

I guess there is no way to receive satisfaction here.

throwaway201606··on How We Justified Piling Debt on Poor Customers
>> When I was at Capital One, I wanted to understand if it was possible to keep loans as an option for the people who have exhausted all their better alternatives—without also causing suffering for those who would be better off forgoing purchases or borrowing money from friends and family. After five years, I concluded it was more or less possible to achieve that goal—to do the good loans without doing the bad loans.

>But I can't see why she thinks that.

The answer, which is this clearly the author's position, is self-evident if one moves from assessing the situation from the profit-motive lens: a stop to the practice of predatory lending.

Earlier, the argument was "Isn't this consistent with poor people needing loans": they don't need loans, they need a livable wage (which I know is a whole different story so won't go into that), but since they can't don't have a livable wage, they need financial support to tide them from non-livable paycheck to non-livable paycheck, that does not cost an arm or a leg, as they make sacrificial decisions as to what to make do with/without.

The argument that people are being given more choice is a lie - there is literally no choice here.

The lending is literary predatory as it is i) from a lender of last resort and ii) comes with interest and fees that would be intolerable to anyone with options.

Non-predatory lending is just one part of what the writer describes as ".. do the good loans without doing the bad loans."

throwaway201606··on Banks, Arbitrary Password Restrictions and Why They Don't Matter
Thank you, much appreciated.
throwaway201606··on Banks, Arbitrary Password Restrictions and Why They Don't Matter
So, am coming back, more than a little humbled...

This security story from Canada came out Friday

https://www.theregister.co.uk/2019/09/18/scotiabank_code_git...

am with an FI (financial institution) in the great white north (I am, of course, not speaking for them in any way here) so this is all very very humbling. One theory that I have heard through my network is that event may be the result of agile / sprint work outside regular process ... but it is an unconfirmed rumor... and I do know for a fact that not all platforms are like this...

The assessment of security capability from the guy who found the code + credentials in the wild is brutal! - '"In my experience, this muppet-grade security is perfectly normal for Scotiabank, as they usually leak information once every three weeks on average," Coulls mused.'

throwaway201606··on Banks, Arbitrary Password Restrictions and Why They Don't Matter
Thanks for taking the time to explain this: it does indeed seem clear that they are just doing username and password detection for access.

A followup question: I have lived in Europe and have accounts in banks in Ireland. For those accounts, actually executing any financial transaction requires entering a one time token generated by a device that uses your debit card and PIN.

Like so:

https://www.youtube.com/watch?v=kEOEQzC8-Fc

Do the banks you tested have a similar setup?

Just trying to find out if these specific banks have chosen to control view transactions with just the username / password but require some other additional authentication for actual financial transactions.

throwaway201606··on Banks, Arbitrary Password Restrictions and Why They Don't Matter
Thanks for taking the time to explain that, much appreciated.

I was not aware about the epistemology / philosophical implications of the "it's magic" comment.

I took the literally reading of your comment.

Can you point me at some stuff I can look at to start learning a little more about this - sounds like the kind of interesting stuff I should be reading late into the night rather than working on the sleep I should be getting.

throwaway201606··on Banks, Arbitrary Password Restrictions and Why They Don't Matter
Thanks for taking the time to explain this.

I get the math and the idea that one password can have all combinations hashed in 161 days for this specific scenario - which is a 6-8 char password that does not allow non-alpha-numerics.

I do think I forgot to add that I was thinking about all of this not just as a theoretical problem but in the context of a single end goal: accessing some random's bank account for some large {randoms} through some front end tool that is protected a 6-8 char password.

Keeping this in mind: running this 161 day process results in a list of 32 billion hashes - useful only for a single account - that you really cannot do anything with since:

    i) you don't have bank's stored hash to test against 
   and 
   ii) you can't use the front-end access to test a hash 


If an attacker has back-end access to some DB or app to test the hash, you didn't need the hash in the first place to do nefarious stuff. You are already in.

Point being that, yes, I do get it now that a 6-8 char password is much weaker in that it can be cracked in 161 days. But it is a really expensive attack to mount for a single account that may not even hold the cost of hardware and time spent mounting it. This strategy just does not scale to huge volumes of accounts.

From a bank's risk management perspective, the potential losses associated with a successful attack of a single account in this fashion are more than manageable. It is cheaper, long term, to refund a clients up to $YYMM than it is to pay for one-time development work across all platforms to remove the 6-8 char restriction.

Remember that security posture here has multiple layers. For example, for accounts with significant funds, you can definitely get in the front end with this approach but once in, you still have to deal with other protection schemes before being able to tap into any funds (e.g. multiple 2FA / RSA / PIN / keyword challenges, IP and/or time of day and/or destination gating etc ).

throwaway201606··on Banks, Arbitrary Password Restrictions and Why They Don't Matter
Am confused here, is there something I am missing ?

Brute-forcing bcrypt-hashed passwords on GPUs has a ridiculously low success rate even on most commonly used password data sets.

Failure rate on passwords outside the most commonly used list is more than 95%

https://arstechnica.com/information-technology/2015/08/crack...

throwaway201606··on Banks, Arbitrary Password Restrictions and Why They Don't Matter
I mentioned signals in another comment in this chain and this is a scenario (for banking specifically) where it makes 100% x 100% sense to kill the session for the client's security.

Like kill it totally totally dead!

Unlike other apps, with online banking, the priority is not to keep you connected.

It is to ensure the person carrying out the activity is whom they really say they are and that it is OK for them to do what they are doing with your account

The security posture is "deny" by default and allow if we can verify this person is whom they say they are.

Think about the signals here:

- connection has changed (from wifi to 4g - that gives you a whole bunch of IP, ISP, routing (hops) etc stuff )

- there is a proxy in the chain now (it is possible to identify the hop from phone to laptop)

- view port is still the same (connection is not the user on their phone, they are on their laptop, connected to a phone)

... then the same thing happens all over again but in reverse when you went back to the laptop.

The bank has no idea whether the proxy is a real phone or a MTM intercept especially since the connection did not initiate from that device but switched in flight.

Would totally have required killing the session if I was responsible for defining scenarios here.

throwaway201606··on Banks, Arbitrary Password Restrictions and Why They Don't Matter
"What's odd to me about this post and all of the responses in this thread so far is that everyone is only thinking about password length as a way to defend against online bruting attempts when in reality long passwords mostly serve to protect against offline bruting attempts. The reason you don't want 6 or 8 character passwords is that when your password hashes get dumped it's a lot easier to crack them."

This is: i) not accurate and ii) bad info

Password hash dumps are worthless if the password hashing scheme used is i)crypto-hashing based and ii) uses salt.

6-8 char passwords are not an issue under this scenario. Current password management best practice is to use both standard crypto-hashing algorithms and salt.

https://en.wikipedia.org/wiki/Salt_(cryptography)

Almost all platforms use standardized crypto-hashing packages that come as standard libraries in the language these days and those require salt. Further, almost all banks will all use these packages.

This is the reason you do not see rainbow tables these days, they are worthless in face of almost any current acceptable crypto-hashing implementation ... assuming one does break rule #1 of crypto and try to roll their own crypto ...

https://security.stackexchange.com/questions/18197/why-shoul... https://www.schneier.com/blog/archives/2015/05/amateurs_prod... .. ad nauseam

Salting also has the additional benefit of making brute-forcing magnitudes of difficulty harder. This is because salting rules can be implement that always add non-standard chars..

https://en.wikipedia.org/wiki/Salt_(cryptography)#Common_mis...

As others have said, the 6-8 chars limits are are a function of legacy system somewhere in the application chain (online banking is never a single platform, it is usually a front-end that talks to a standard backend that tellers, operations etc also access, usually some type of greenscreen app - which is where the password hashes end up).

throwaway201606··on Banks, Arbitrary Password Restrictions and Why They Don't Matter
For the really large banks: $XYYMM (i.e. hundreds of million dollars aka the cost of doing business) across all lines of business.

All this is mostly public info as it has to go into financials, you can find it under "Operational Losses" for any public bank (Note that "Operational Losses" are not the same as "Operating Losses").

A sample multi-year summary can be found here from an industry body in Europe for losses for debit. (losses are demonimated in Euro):look at page 7 under the last column for the rows "Retail Banking". Important to note that credit ops losses are an order (or maybe two) of maginitude higher.

https://managingrisktogether.orx.org/sites/default/files/dow...

← PreviousPage 2 of 3Next →