Hacker News new | ask | show | jobs
by raesene9 1535 days ago
On the first point, I don't see any particular reason why banking shouldn't go with cloud. Obviously banking has regulatory hurdles and things like availability are important so it'll require a specific architecture to help achieve that, but in general shouldn't be a problem.

On the second point, I'd say it depends on the level of granularity and detail. Here they're describing general mechanisms and they're not saying that this is all they do, so I think it's a good thing.

In general relying on obscurity for your security is a bad idea, as attackers will often find a way to get that information. That said I wouldn't give attackers a complete schematic of my env. and every protection, no sense in making things easy for them :)

1 comments

All you need is a single disgruntled ex-employee to be bribed by hackers to reveal your complete security design.
Social engineering is likely the easiest way to get through security systems.