logoalt Hacker News

jpollocklast Friday at 11:47 PM3 repliesview on HN

If the majority of your customers are good, failing closed will cost more than the fraud during the anti-fraud system's downtime.


Replies

prmoustacheyesterday at 1:50 PM

If that is the mindset in your company, why even bother looking for vulnerabilities?

everforwardyesterday at 2:31 PM

You are really running with scissors there. If anyone with less scrupulous morals notices, you’re an outage away from being in deep, deep shit.

The best case is having your credit card processing fees like quadruple, and the worst case is being in a regulated industry and having to explain to regulators why you knowingly allowed a ton of transactions with 0 due diligence.

lazyasciiartyesterday at 4:32 AM

Until any bad customer learns about the fail-open.

show 1 reply