|
|
Log in / Subscribe / Register

Banking

Banking

Posted Aug 3, 2026 19:29 UTC (Mon) by corbet (editor, #1)
In reply to: Banking by pizza
Parent article: SQLite Critical CVEs or LLM Slop? (JFrog blog)

You know, when people start filling the space with tedious quibbles like this, I strongly regret having ever added the ability to post comments to LWN.

Is your real point that the original poster should have said "financial services" rather than "banking"?


to post comments

Banking

Posted Aug 3, 2026 19:54 UTC (Mon) by pizza (subscriber, #46) [Link] (2 responses)

> Is your real point that the original poster should have said "financial services" rather than "banking"?

I don't know if they had meant to use the word "banking" as a synonym for generic "financial services" or the more narrow "bank account" sense. Either way, they were factually incorrect, only certain types of financial service providers place any sort of obligations upon a business' internal IT practices.

The main ones that do are payment processors (the PCI-DSS is quite a beast, as I'm sure you are well aware) and providers of certain types of insurance looking to lessen the risk of taking you on as a customer. But simply opening or accessing bank accounts/lines of credit, most types of insurance, brokerages, etc etc? Nope.

Banking

Posted Aug 3, 2026 23:15 UTC (Mon) by WolfWings (subscriber, #56790) [Link] (1 responses)

For any company interacting with the internet they are all functionally one and the same. You are (accidentally I hope) XKCD/2501'ing here.

"Banking" access is a well-understood catchall for payment handling, payroll, etc, all of which are the source of many if not most audit requirements for any given company. And yes, all of those require opening an account, so technically that's rolled up in things too at some layer I suppose even.

Anyone that works B2B IT support runs into this constantly, doesn't matter if you're a cloud provider, storage vendor, networking gear, VoIP service, whatever, it's where easily 50% or more of the "Hey so our auditor reported these CVE's..." tickets come from if you inquire is just a non-technical "banking" response back.

Banking

Posted Aug 4, 2026 12:30 UTC (Tue) by pizza (subscriber, #46) [Link]

> "Banking" access is a well-understood catchall for payment handling, payroll, etc, all of which are the source of many if not most audit requirements for any given company.

As an entire blanket category, sure. But my entire point is that the sub-categories are *very* different and shouldn't be lumped together.

These are the entire "IT requirements" for most businesses that take credit cards:

* Working internet connection and power source for the payment-processor-supplied(+managed) payment terminal

Meanwhile, these are the entire "IT requirements" for nearly everything else:

* Internet-capable device with a relatively up-to-date web browser

That's it.

Now if you run things in-house instead of contracting it out to specialists (because this saves you money at larger scales), sure, there _may_ be additional requirements for _some_ sub-categories, but the specific details vary considerably. The critical question is "who is on the hook should $bad_thing occur". If it's an external entity (eg merchant/payment processor or insurance company) then they may contractually impose requirements as a condition of service.

Of course there's also increasing levels of regulatory crap you have to deal with the more stuff you do in-house, but that's imposed by the government, not a "financial services" provider.

(BTW, most of my career has been spent at small companies for whom *I* was effectively IT department. So I'm more than a little familiar with this crap)

Banking

Posted Aug 6, 2026 19:49 UTC (Thu) by smoogen (subscriber, #97) [Link]

My apologies Jonathan for starting this.. I should have been clearer about payment processing and financial services versus 'banking access'.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds