Hacker News new | ask | show | jobs
by ithkuil 1575 days ago
Security by obscurity
2 comments

Well, no, they are just controlling the whole line of delivery for the data packages; its not uncommon in critical infrastructure, that you have to deploy some special hardware stuff for whatever security reasons.

For sure, the typical HN-mentality is: "there is no security and since this a dumb bank/financial-service, they are just trolling and they dont know what they are doing" - no, let me tell you that you are wrong with this assumption: SWIFT is pretty secure and there haven't been any larger (successful) attacks on the network itself (hint Central Bank of Bangladesh losing 90m in a CEO-scam is not a problem of SWIFT, same for similar cases)

> is not a problem of SWIFT, same for similar cases

Perhaps it was not in SWIFT's domain of responsibility. But it was for sure a problem for them and it's why they started CSP.

IT, even when huge sums are spent on it, is still seen as a cost center (rather than a competitive advantage) at the vast majority of banks.

However, as the other reply said to you... I've really not seen any evidence the SWIFT system isn't decently well constructed. When attacks (such as Bangladesh) have happened it has been due to not following best practices as established by SWIFT and other institutions.