|
|
Log in / Subscribe / Register

Banking

Banking

Posted Aug 4, 2026 12:30 UTC (Tue) by pizza (subscriber, #46)
In reply to: Banking by WolfWings
Parent article: SQLite Critical CVEs or LLM Slop? (JFrog blog)

> "Banking" access is a well-understood catchall for payment handling, payroll, etc, all of which are the source of many if not most audit requirements for any given company.

As an entire blanket category, sure. But my entire point is that the sub-categories are *very* different and shouldn't be lumped together.

These are the entire "IT requirements" for most businesses that take credit cards:

* Working internet connection and power source for the payment-processor-supplied(+managed) payment terminal

Meanwhile, these are the entire "IT requirements" for nearly everything else:

* Internet-capable device with a relatively up-to-date web browser

That's it.

Now if you run things in-house instead of contracting it out to specialists (because this saves you money at larger scales), sure, there _may_ be additional requirements for _some_ sub-categories, but the specific details vary considerably. The critical question is "who is on the hook should $bad_thing occur". If it's an external entity (eg merchant/payment processor or insurance company) then they may contractually impose requirements as a condition of service.

Of course there's also increasing levels of regulatory crap you have to deal with the more stuff you do in-house, but that's imposed by the government, not a "financial services" provider.

(BTW, most of my career has been spent at small companies for whom *I* was effectively IT department. So I'm more than a little familiar with this crap)


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds