[HN Gopher] Global IT outage shows dangers of cashless society, ...
___________________________________________________________________
Global IT outage shows dangers of cashless society, campaigners say
Author : rntn
Score : 128 points
Date : 2024-07-20 18:52 UTC (4 hours ago)
(HTM) web link (www.theguardian.com)
(TXT) w3m dump (www.theguardian.com)
| rbanffy wrote:
| It highlights the risk of a fragile infrastructure.
| gjsman-1000 wrote:
| All infrastructure is fragile and always will be.
|
| Bridges collapse; police go corrupt; electricity has outages;
| gasoline suffers price shocks; governments have a 100% failure
| rate; an 1870s-style solar flare would send us back to medieval
| times.
|
| All we can do is:
|
| A. Diversify, under the belief nothing is infallible; and even
| perfect engineering can experience catastrophic failure
|
| B. Enjoy what we have today, knowing it is a gift, not a right
|
| Also, while we blame CrowdStrike, let's not forget that SSH was
| within weeks of being backdoored on a global scale. The power
| that would have unleashed (and proxy power, I.e. breaking into
| CloudStrike and then Windows by extension) very well could have
| ended the internet.
| dave4420 wrote:
| Some infrastructure is more fragile than others.
|
| 2020s UK electricity infrastructure is more reliable than
| 1980s UK electricity infrastructure, for example.
| rbanffy wrote:
| And with the push towards renewables and battery storage,
| 2040's energy grid is expected to be MUCH more robust than
| 2020's.
| phyalow wrote:
| The inevitable march of entropy.
| Angostura wrote:
| > A. Diversify, under the belief nothing is infallible; and
| even perfect engineering can experience catastrophic failure
|
| Hence keeping cash alive has it's advantages
| 1970-01-01 wrote:
| I wouldn't say fragile. A bit of Roman stuff is still
| functional today. The pyramids are holding up too. Cathedrals
| also have a massive stability streak. The stuff that has been
| falling over is mostly brick, steel, and concrete. And that's
| due to lack of required maintenance. I could even use the
| opposite word to describe them: strong and solid.
| brookst wrote:
| But isn't that survivor bias? The Romans built all sorts of
| things that didn't last.
| kibwen wrote:
| And plenty of cathedrals collapsed without proper
| maintenance, or were destroyed by invaders, or had their
| stones taken by locals for use in building. All it took
| was a spark in the wrong place to destroy Notre Dame.
| eponeponepon wrote:
| On a long enough timescale, all of these things are dust,
| though.
|
| ...basically, label your axes.
| rbanffy wrote:
| Or a planetary nebula
| derac wrote:
| I agree with your main point on entropy, but
|
| "an 1870s-style solar flare would send us back to medieval
| times"
|
| This is not true and it would have no effect on
| microelectronics.
| gjsman-1000 wrote:
| It doesn't really matter what happens to your
| microelectronics if there's no power anywhere.
|
| https://en.m.wikipedia.org/wiki/Carrington_Event
| echoangle wrote:
| It actually does, restoring power is much easier than
| restoring power and replacing every electronic thing in
| existence
| chrisjj wrote:
| Batteries and generators will still work, surely.
| rbanffy wrote:
| > All infrastructure is fragile and always will be.
|
| No, and it doesn't need to be. We can build redundancy on
| every level. We can plan for failure and prepare for
| contingencies. We alwas need a plan B (and C and D for
| critical services). Will it be efficient or cheap? Of course
| not - we'd be building two for the price of two, but being
| sure that, when one fails, we have a redundant one to catch
| the fall of civilization.
|
| We can't just optimize away every gram of safety and hope
| everything goes to plan (as they did in this case). Hope is
| not a strategy.
| lawn wrote:
| "Fragile" isn't the same as "will eventually fail".
| ghaff wrote:
| Yeah. If I can't pay by credit card I don't assume I can just
| plop down cash for the most part.
| IAmGraydon wrote:
| You...don't? I'm not sure I understand what you mean.
| Filligree wrote:
| In a number of countries there are a lot of shops that
| don't accept cash. Norway, for example, though there's a
| law slated for implementation soon that will force them to.
| manuelmoreale wrote:
| Such as? Not debating if you're right or not, just want
| to search if it's actually legal there or if it's just
| something that's happening at a cultural level.
| echoangle wrote:
| At least in Germany, it's legal to deny cash payment if
| you make it clear before the transaction. If you post
| signs at the entrance which can't be missed, you can
| exclusively accept card payment. I'm not sure I've ever
| seen that in practice though.
| Filligree wrote:
| I would assume it's legal, considering they're about to
| make it illegal.
| ghaff wrote:
| If a retailer can't process transactions (e.g. look up
| prices) being able to give them a piece of paper isn't
| necessarily better than trying to process a credit card.
|
| ADDED: And yes. Sometimes places are simply not setup to be
| able to take cash.
| olyjohn wrote:
| What retail store doesn't have price tags on their items?
| ghaff wrote:
| Most, in large stores/chains. I'm not sure any of the
| large US stores I shop in have a price tag on the item
| any longer.
| lostlogin wrote:
| > I'm not sure any of the large US stores I shop in have
| a price tag on the item any longer.
|
| But it's in the shelf surely? Probably on an e-ink
| display.
| ghaff wrote:
| But what good does that do at the checkout if computer
| systems are down? And no supermarket I frequent has eink
| displays on the aisles.
| card_zero wrote:
| Besides which the central shelf label server is probably
| also down.
| kccqzy wrote:
| And do you expect the cashier to walk to the shelf for
| every single item in order to look up prices?
| Cerium wrote:
| To this point, I have shopped in grocery stores during
| power outages. The checkout terminals usually have
| battery backup and a local copy of the current prices to
| enable processing cash transactions.
| ghaff wrote:
| Yeah. I've (rarely) been able to pay for an item without
| a price sticker in cash when credit card transactions
| were down.
| echoangle wrote:
| The point they're making is that if there is a system
| failure which makes card payment unavailable, the failure
| could also have taken out the cash register entirely. And
| because most products only have a bar code on them which
| has to be scanned to get the price, it's possible that
| the store can't sell anything (unless they want to look
| up the price of every item at the shelf).
| manuelmoreale wrote:
| Unless he means online transactions I'm also quite lost.
| Never seen a place that ONLY accepts cards in my life. I
| don't think it's even legal here.
| brookst wrote:
| Seattle here. Many restaurants have signs saying cards
| only, no cash accepted. I suspect if you ate a $100 meal
| and only had cash they would find a way to accept it, but
| they at least purport to have that policy.
| noduerme wrote:
| Oregon requires businesses to accept cash. (With some
| exceptions like automated parking structures). It's
| shocking to me that Washington doesn't. I remember going
| to that creepy amazon pick your own and walk out store in
| Seattle and thinking wow, guess that's one way to keep
| the homeless out.
|
| A few bars in Portland are still cash only!
| ghaff wrote:
| Even in Massachusetts which (theoretically) requires
| restaurants to accept cash, parking garages are often
| cash only and, of course, highway tolls require a ton of
| hoops if you're not just auto-billing by card.
|
| Funnily enough, I was on a Whale Watch the other day in
| MA which was cash only. Didn't buy anything but it was
| presumably because they were out of cell coverage.
| ghaff wrote:
| Parking garages = card only.
| ghaff wrote:
| I have absolutely seen it. We could start with planes
| which is of course an edge case. But it's the case
| elsewhere as well. And even where illegal, it happens.
| sebastiennight wrote:
| I've found that an increasing number of chains (eg
| fitness locations, some restaurants and service
| providers) use the no-cash policy as a way to (a)
| discourage staff from stealing and (b) get more valuable
| data on each buyer.
| undebuggable wrote:
| The things do not fallback but rather propagate causing an
| avalanche. The only alternative to electronic payments which
| always boil down to some form of VISA or Mastercard card, is
| cash.
| hdhshdhshdjd wrote:
| The cash is subject to inflation and poor central banking
| decisions. To be really safe, let's just go back to a barter
| system. Just bring five eggs to the pub and get a pint.
| goatlover wrote:
| And what do I give the power company?
| nicce wrote:
| You promise to cut the trees under their power cables on your
| land
| verandaguy wrote:
| What if you rent or own a condo?
|
| What if you don't own tree cutting equipment?
|
| What if you have a disability that prevents you from
| cutting trees?
|
| What if your property doesn't have trees to cut?
| eponeponepon wrote:
| It's fine, it's worked for millennia - you simply gather
| your many belligerent sons, hand them large clubs and
| send them to batter the power company's director till he
| gives in.
| hdhshdhshdjd wrote:
| Ten eggs per power, obviously.
| majorbugger wrote:
| You're fighting a strawman. Noone is advocating pure cash here,
| just that the cash should remain an option.
| hdhshdhshdjd wrote:
| To be fair, I'm not sure how many straw men will get you a
| pint at most public houses these days.
|
| I'm only familiar with egg-to-pint exchange ratios, but then
| again most of my personal liquidity is tied up in a henhouse
| currently.
| dgb23 wrote:
| Was that ever a thing on a large scale? From reading Debt by
| Graeber I got a different impression.
| WorkerBee28474 wrote:
| That's funny, but more seriously if we look for a solution
| that:
|
| - Is not subject to inflation or poor central banking decisions
|
| - Does not rot or spoil
|
| - Is a single interchange format that can fulfil the 'double
| coincidence of wants'
|
| - Has no single point of failure.
|
| Then that currency seem to exist in the forms of gold or
| crypto.
| neonbrain wrote:
| The problem is that gold and crypto are priced in relation to
| fiat and if fiat ceased to exist, you wouldn't be able to
| price either. When splitting gold or crypto among fellow
| citizens (yes, these assets will become shared between
| everyone), you wouldn't be able to do so without some form of
| IOU, which effectively would become another form of fiat.
| It's a catch-22 situation: while fiat exists, gold-bugs and
| crypto-bros feel smug, when there's no fiat, everyone is
| suddenly unhappy.
| czl wrote:
| To maintain stable short-term prices, active regulation of
| currency supply is necessary. Without it, currency value
| fluctuates with supply and demand, making prices unstable.
|
| In the long term, a small amount of inflation is needed to
| discourage hoarding. Without it, people might treat currency
| as an investment, leading to unstable prices like we see with
| gold and Bitcoin.
|
| Currency should be stable, like standard measures (Kg, Foot)
| that don't change in the short term. It also functions like a
| store cart for shopping. If carts become scarce, shopping is
| difficult. Therefore, there must be an incentive to return
| the cart for others to use.
|
| Another purpose of currency, albeit controversial, is to
| manage debt accumulation. Historically, societies faced
| growing debt and used "debt jubilee" events to reset, which
| disrupted commerce. Modern societies address this through
| currency inflation.
|
| If gold or crypto were effective currencies, prices would be
| advertised in Bitcoin or gold. The fact that they are not
| suggests they don't serve well in this role.
| whalesalad wrote:
| Shows the dangers of infrastructure running on Windows. There are
| ways to build resilient systems that can survive shit like this.
| Look at the internet. Look at the phone system.
| gjsman-1000 wrote:
| Last month; SSH was nearly backdoored with nobody noticing.
| _SSH_ , open source software, and one of the most important
| pieces of software ever written for security, was extremely
| close to failure.
|
| If that had happened, an attacker very well could have ended
| the entire internet as we know it. Imagine if that hacker
| merely used that backdoor to get into Windows Update servers,
| Google Play servers, or sent out a CrowdStrike update.
|
| We were within weeks of nothing being safe.
| undebuggable wrote:
| A round decade after Heartbleed... it just periodically
| reminds that it needs some attention and love. People just
| use it paying nothing.
| hypeatei wrote:
| No security vulnerability, even an OpenSSH bug, would result
| in the internet being taken down overnight. There are
| organizations and people who apply "security in layers"
| mindset so that one slip up doesn't result in a complete
| takeover of systems.
| connor4312 wrote:
| Crowdstrike could have deployed the same broken code in their
| Linux or macOS agents. Nothing much for Windows to do if a
| kernel driver is segfaulting (when disabling it could be
| dangerous for users.)
| whalesalad wrote:
| macOS and Linux do not have nearly as much a need for
| ridiculous endpoint security tools like this to begin with.
|
| The world running on Windows is a monumental waste of
| resources and a huge security threat. This will happen over
| and over again.
|
| The fact that even dummy little terminals that are strictly
| responsible for showing flight arrivals and departures was
| impacted by this is hysterical. Why was that not an android
| or chromeos device with an immutable filesystem, A/B blue
| green update strategies etc.
| hypeatei wrote:
| > The fact that even dummy little terminals that are
| strictly responsible for showing flight arrivals and
| departures
|
| Exactly. It seems like we're deploying very capable and
| complex devices for a simple task which is showing a couple
| pages of text in a table format.
| vbezhenar wrote:
| So the question is why we need CrowdStrike software in the
| first place? Why our systems are not secure enough that
| companies feel the need to install additional security
| software? Obviously demand for secure operating system is
| there. CrowdStrike company valued at $80B, so lots of money
| for Microsoft and other operating software vendors to grab.
|
| I do understand that main driver behind CrowdStrike
| installations is compliance checkbox. It still keeps the
| question, unless we assume pure corruption. But I've heard
| opinion from security experts, that this software really
| improves Windows security.
| photonthug wrote:
| serious question, does anyone really think Linux antivirals
| are good or necessary, particularly if they are active
| measure kernel things and not just passive scanners?
|
| I have only seen people use them when windows it departments
| suddenly have to pretend to be cloud savvy, or when
| enterprisey infosec teams are looking for more vendors to
| bloat up their budgets. If it's written in contracts, it's
| not the customers demanding av on ephemeral cloud servers,
| it's the home team bloating costs so they can cut them later
| for a raise and applause.
|
| Aaaand whenever it goes that way, antivirals affect
| performance and stability with random problems, always
| hurting more than they help
| whalesalad wrote:
| Nine times out of ten it's not even for security it's for
| checking some kind of auditing compliance box. We're
| perpetuating this nightmare quagmire of shit and no one
| understand how it works.
| photonthug wrote:
| Any details on what compliance regime specifically
| requires it for Linux tho, and whether it differentiates
| static servers from ephemeral? I'm just curious since you
| always hear "compliance" but I've never actually seen the
| requirement coming from anywhere except windows sysadmins
| who are out of their element
| whalesalad wrote:
| Part of the issue is that compliance is so broad and will
| vary from industry to industry, state to state and
| country to country. If you're in defense and work with
| the government you're requirements will be different
| versus healthcare or the education sector.
|
| The baseline is NIST guidelines but even that is a huge
| can of worms. It's difficult to simply say "yes we're
| compliant" especially in large organizations.
| https://www.cuicktrac.com/nist-
| compliance/nist-800-171-compl...
|
| A lot of orgs get overwhelmed by this, and so they
| outsource the effort to a third party.
| dafelst wrote:
| Crowdstrike also managed to take down a bunch of Debian boxes
| not too long ago - this is not a Windows problem, this is a
| problem with a vendor product auto deploying bad kernel
| modules.
| whalesalad wrote:
| It's actually a problem with the implementor allowing
| software to update itself blindly like this. I'd never enable
| "auto-update" in critical infrastructure. Completely
| laughable minor league move.
| billy_bitchtits wrote:
| The bitcoin network managed just fine.
|
| Tick tock next block.
| wepple wrote:
| My barter system of growing vegetables to trade with managed
| just fine too.
|
| But it was useless for buying gas with, unfortunately.
| ben_w wrote:
| The bitcoin network can't handle just income and (possibly even
| or) rent/mortgage payments in just the Netherlands.
|
| If it had to also cover an average of one meal payment per
| person per day, it couldn't handle just Coventry.
|
| Extra payment layers quickly start to look like banks with all
| the same kinds of expectations and failures popping up.
| verandaguy wrote:
| The Bitcoin network is slow to verify and has the environmental
| impact of a medium-sized industrialized economy just to run the
| thing. It's also exceptionally volatile compared to fiat
| currencies (though at this point pretty stable compared to
| other cryptocurrencies), and the fact that it's deflationary
| makes it difficult to justify as a solution in a still-growing
| worldwide economy.
| FpUser wrote:
| >"Global IT outage shows dangers of cashless society"
|
| No shit Sherlock. It takes pure genius to guess that we've had,
| and will always have technological / infrastructure failures.
|
| For our particular case politicians who are pushing for
| elimination of cash are either criminals or brain dead imbeciles.
| Not sure which case is worst.
| mcny wrote:
| It highlights the dangers of a mono culture as well.
|
| Most importantly though, I remember my history professor who
| always said, "follow the money!" Do the CEO and the board have to
| pay (either in money out of pocket or time served in prison) for
| these problems (outages / oil spills / global warming / what
| not)? If not, what incentive do they have to make the likelihood
| of these problems dial down to zero?
|
| I like this article
|
| https://archive.ph/1ekmk
| zoobab wrote:
| No fines, no prison.
| hoffs wrote:
| It's up to the customersthat were affected, they could sue
| for damages, but doubt many will do
| mcny wrote:
| I anal so I don't really know what I am talking about but I
| am hoping for criminal liability as opposed to civil
| liability. For example, I am thinking if I kill someone
| with no next of kin, I still have criminal liability even
| if nobody from the victim's family is there to sue me.
| didntcheck wrote:
| The company does have to use its assets to pay anything it's
| liable for, yes. It sounds like essentially arguing against the
| concept of limited liability for the owners and investors? I
| would regard LL as generally a good thing. Without it, it would
| be a much bigger ask for anyone to start up a business when
| they're putting their own house and everything at risk. And I
| expect it would lead to an even further skew of already-rich
| people dominating investment and company ownership
| bryanlarsen wrote:
| > start up a business when they're putting their own house
| and everything at risk
|
| Every hardware startup founder I've been involved with has
| used their house and/or their retirement savings to back
| their operating loan.
|
| I think the advantages of incorporation have been well
| established by now, and believe that partly removing limited
| liability would not significantly effect incorporation rates.
| inglor_cz wrote:
| There is a catch in that.
|
| Customers want cheap services, and a corporation that would
| employ three times as many QA people would be disadvantaged
| against the ones that just wing it.
|
| It will take several incidents such as this, before the market
| starts understanding that some extra cost is tolerable for
| having some sort of warranty.
| huijzer wrote:
| Yes I agree with you, the article and Taleb. These corporations
| which the whole West depends on sound nice in theory but cause
| the system as a whole to be brittle. I think there is
| definitely a market for writing software for very specific
| areas. Like, I donno, an office productivity suite hyper
| optimized for the European market. It sounds impossible but if
| you obsess over quality then I think it's possible to get (very
| happy!) customers.
| ffsm8 wrote:
| > _It highlights the dangers of a mono culture as well._
|
| The devil is in the detail though. You can have an incredibly
| stable distributed system with limited failure modes.
|
| lots of examples around, a pretty well known one would be VISA
| transactions. Each acquirer can fail separately, and even if
| they're failing, some of their terminals will keep going
| without any impact. And the remaining acquirer will also keep
| chugging along.
|
| It's still objectively a monoculture, as Amex and MasterCard
| are pretty rare on global scale, while visa is basically
| everywhere
| givemeethekeys wrote:
| Couldn't agree more. Incentives rule the world!
|
| Doing the right thing isn't always aligned with winning.
| Shareholders can sue a company for not doing whats in their
| best interest. Instruments such as public benefit corporations
| are relatively new. Employee owned corporations aren't very
| common - almost non-existent in tech / biotech /pharma / energy
| / transportation.
| thrill wrote:
| It certainly shows the dangers of non-rigorous testing before
| transmission and non-rigorous testing before acceptance, but
| first-to-market and ignoring technical debt will remain the
| business mantra.
| bamboozled wrote:
| Amen.
|
| _Martin Quinn, campaign director for the PCA, said using cash
| allowed for anonymity. "I don't want my data sold on, and I don't
| want banks, credit card companies and even online retailers to
| know every facet of my life," he said. Budgeting by using cash is
| also easier for some, he added._
|
| Cash is also the only payment system I can think of which is
| truly "private". I think this is important too.
| gtk40 wrote:
| You're probably right, but it doesn't always feel that way when
| you have serial numbers on every piece of currency. And coins
| are so uselessly low value today that they're hard to use.
| bamboozled wrote:
| It's pretty hard to track serial numbers , you can easily
| wash the money" yourself ?
| inglor_cz wrote:
| Some ATMs likely already track serial numbers, so you know
| when the banknote left the bank's custody and who withdrew
| it, using which card.
|
| You can also track serial numbers when businesses return
| daily cash collections to their bank.
|
| Especially the biggest denominations won't be passed back
| to other customers in the meantime, but rather sent back to
| the bank early.
| greenthrow wrote:
| Is it really private? You have to use it in person and every
| place of business has cameras nowadays.
| 1_1xdev1 wrote:
| It's way more private than all of your transaction history
| rolled up by your card issuer.
|
| Does some central authority have access to and the compute
| power to correlate all of the data available in those video
| feeds? No
| hoffs wrote:
| You only need to know where the person was or when crime
| was committed,
| 1_1xdev1 wrote:
| You're right but I don't think we're solving for the same
| thing.
| willmadden wrote:
| >Does some central authority have access to and the compute
| power to correlate all of the data available in those video
| feeds? No
|
| * _TrapWire, the bank secrecy act, and the Utah datacenter
| enter the chat*_
| mrmetanoia wrote:
| the lack of privacy at a business isn't a problem baked into
| cash. cash helps solve that problem because I don't need to
| go to a place of business to use it. It can be exchanged
| anywhere in reasonable amounts, and I don't have to deposit
| it I can just keep it and use it.
|
| my wife and I always keep some cash on hand in case of some
| sort of problem with the card, or tap device etc. never had
| my cash declined because a computer thought some other
| purchases that afternoon looked suspicious.
| koonsolo wrote:
| Monero too. But I guess suggesting crypto on HN will not get me
| any upvotes ;).
| willmadden wrote:
| No, it will not. They are missing the financial and
| historical perspective here to appreciate it.
| hypeatei wrote:
| I still use cash at a few small businesses who don't take cards
| because of fees and management overhead.
|
| Perhaps if we capped fees and made accepting cards (or any type
| of electronic payment) more of a utility then it wouldn't be so
| cumbersome and costly.
| elforce002 wrote:
| Hear, hear! There are no outages, hacks, etc... when using cash.
| I use credit cards as much as anyone else but also use money at
| every opportunity. Shops need to use collect on delivery as a
| form of payment too.
| blackeyeblitzar wrote:
| Cashless societies are dangerous purely for reasons of privacy
| and freedom. The ability to trade without government oversight
| matters. I am appalled to see government run services, hospitals,
| and stores near me start to refuse cash. That shouldn't be legal.
|
| Not to mention, cashless systems like Visa and Mastercard and
| PayPal are subject to private overlords that may scrutinize or
| ban your transactions.
| RcouF1uZ4gsC wrote:
| Actually the ultimate fallback is force.
|
| So to really diversify you should stock up on weapons and
| ammunition and gather a group of likeminded people and train
| together in a fortified location.
|
| Of course, that is likely to have its own issues.
| sllabres wrote:
| I found this page [1] interesting in regard to cash supply in
| Sweden, as it is a country always reported with a high affinity
| to online payment and statistics [2] (from 2019) seems to support
| that statement.
|
| [1] https://www.riksbank.se/en-gb/payments--cash/payments-in-
| swe...
|
| [2] https://www.statista.com/chart/17307/paying-with-cash-
| europe...
___________________________________________________________________
(page generated 2024-07-20 23:13 UTC)