• nomad@infosec.pub
    link
    fedilink
    arrow-up
    8
    arrow-down
    1
    ·
    12 hours ago

    I have been working in software for quite a while and one thing has remained constant over the years: users will find to exploit any feature in a way it was not intended to if it suits their needs.

    We usually fix that shit by adding another field for remarks or maybe adding a flag that allows to tell anybody not to touch that even with a ten foot pole…

    That there haven’t done that and instead something like this is common in banking, not just at one bank, is a dead giveaway on the state of the software banks are using.

    There is usually a reason why they refuse to touch anything. In banking software is old… As in older than me. My dad used to build this software when he was in his prime which was about 60 years ago. It hasn’t changed since then…

    • n7gifmdn@lemmy.ca
      link
      fedilink
      English
      arrow-up
      6
      ·
      12 hours ago

      Yeah it did, the used to use two digits for the year, than they had to change it because people’s credit cards were being denied for expiring in 2000

    • halcyoncmdr@piefed.social
      link
      fedilink
      English
      arrow-up
      4
      ·
      11 hours ago

      Don’t discount the chance that implementing a better solution could be functionally impossible.

      Chase still has their systems running through a COBOL mainframe after all.