5 ms·
Even though they weren't affected much and no one would have called them out if they didn't do this, the fact that they did such a nice job of dissecting the si
by libeclipse 10y ago
Even though they weren't affected much and no one would have called them out if they didn't do this, the fact that they did such a nice job of dissecting the situation and deploying the appropriate measures is really, really good.
Love monzo. <3
- lumisota 10y agoWhile it should be applauded that they responded promptly, it needs to be remembered that this is a regulated, licensed bank that proxied sensitive customer information via a (now compromised) third-party. We should expect this kind of disclosure from such organisations, not be surprised by it.
- mintplant 10y agoMy thoughts exactly. As a bank, allowing Cloudflare to MITM their customers' financial data, presumably so they can save on bandwidth, seems inappropriate.
- obeattie 10y agoThe only reason to consider Cloudflare, for us, is DDOS mitigation.
- mintplant 10y agoIs it necessary to allow them to terminate/decrypt your TLS connections in order to provide DDOS mitigation? There are other providers besides Cloudflare in this space. Isn't the DDOS mitigation undermined by exposing the API used by your apps directly?
- user5994461 10y agoThe (almost) only other provider is Akamai and it's the exact same thing. Seriously, CloudFlare is doing nothing new and nothing fancy.
- mintplant 10y agoAre you claiming that Cloudflare and Akamai are the only providers of DDoS mitigation services? A simple web search will show otherwise.
- shawabawa3 10y agoDid you read the post? They don't use cloudflare to MITM customer data.
- grzm 10y agoPlease don't imply that someone hasn't read the article. From the guidelines: "Did you even read the article? It mentions that" can be shortened to "The article mentions that." https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- mintplant 10y agoI did read it, but on a second look, I see I missed that "Monzo.com [the web portal] does not process any sensitive information". Thanks for pointing that out.
- lumisota 10y ago> "Our developer API does sit behind Cloudflare with all of its traffic proxied through their service." .. "Data sent to and from our developer API may contain the following information:" .. "Customers’ personally identifiable information"
- libeclipse 10y agoIn an ideal world, yes. But this is the world where we live, and what monzo did is rare enough to warrant surprise.