3 ms·
There are a number of reasons not to put critical business systems on top of EC2. First and foremost, if you don't have control of who can physically access yo
by rcoder 19y ago
There are a number of reasons not to put critical business systems on top of EC2.
First and foremost, if you don't have control of who can physically access your hardware, you can't make any real assurances about the privacy and integrity of your data. I don't care how much you trust Amazon with your personal credit card and shipping information -- you are taking a big risk putting your customers' data there, too.
Secondly, EC2 has no SLA at all. Given Joel's (strong) argument about the limited usefulness of SLAs in general, that may not seem like a big deal, but the lack of any firm commitment on Amazon's part pretty much means that you're SOL if there are any major problems.
Finally, EC2 absolutely does not protect you from issues like mis-configured network hardware. Amazon may have incredibly redundant connectivity, including data centers in different geographic regions, but that redundancy doesn't necessarily benefit your virtual machines in the way it does Amazon's core business applications. One VM instance is still tied to one physical box hosting it, and if that box goes down, you'll lose that host and any data it hasn't flushed elsewhere on the network.
That's not to say that EC2 doesn't have its uses; I just couldn't imagine putting your mission-critical apps on it. Stick with prototyping, testing, batch-processing, and the occasional extra capacity for unexpected spikes in load, and you should be fine.
- gibsonf1 19y ago1. Without password and encryption keys, access to the hardware is meaningless from a data security perspective. 2. I am pretty confident that Amazon's ability to keep the computers running is better than most other options. And unless their entire service goes down as well as the entire S3 grid, we can very quickly launch a new instance with no data loss (we have a hyperactive back up strategy to S3 to prevent data loss in case of an EC2 instance failure) 3. We can launch a new instance in a very few minutes. So if anything, this seems like an ideal environment where uptime is extremely good, and in the case of a failure, recovery is extremely fast. I'm not sure where we can get similar service? The S3 is especially good in terms of multiple backups in different regions - hard to beat for assuring business clients who can't afford to loose data that their data won't be lost.
- run4yourlives 19y ago>1. Without password and encryption keys, access to the hardware is meaningless from a data security perspective. Are you shitting me? What school did you go to?
- gibsonf1 19y agoI guess we need to concretize this: Someone decides that the data on my system is valuable and wants to steal it. They find out that we're running on EC2 with backup to S3, and they want to locate the equipment. How in the world would they do it? I have no clue where the hardware is that hosts our service. Much easier to break into someone's office and get the equipment directly, or to break into a smaller host and grab the equipment. With the cloud, finding the actual hardware in use seems extremely difficult - which seems to dramatically increase your security against a hardware theft as opposed to self hosting.
- run4yourlives 19y ago1. You're assuming the threat is targeted. You'd be just as liable (and it would cause you just as much damage) if Amazon's janitor decided to walk off with a couple of hard drives. 2. You not knowing which server your data is on is just as bad. You can't actually guarentee me that my data hasn't been stolen. You have no way of knowing.