4 ms·
Cloud is a no-go if you're handling sensitive client data (like all of their passwords)
by BrainInAJar 10y ago
Cloud is a no-go if you're handling sensitive client data (like all of their passwords)
- jfoutz 10y agoHuh, interesting. I know Amazon, at least, has provisions for HIPAA, [1] which seems pretty strict. Having to notify newspapers in case of breach and some pretty stiff fines. I know a bunch of places do credit card processing on AWS. PCI is pretty strict as well. Is the big concern physical access? Or is there a subtle hack to escape the VM you're running in? I'm just having a hard time seeing the difference between a vm connected to the internet at the office, a colo server and a aws instance. I guess you must be referring to minimizing surface area, not a proven attack. It's tempting to trust your team, and you need to. If you're doing real, regular audits of access controls and have some pretty robust physical security, that could be a win. Seems like you'd have to be a pretty big shop to do security "right". [1] https://aws.amazon.com/compliance/hipaa-compliance/ https://aws.amazon.com/compliance/hipaa-compliance/
- BrainInAJar 10y agoCompliance is not security. A sophisticated attacker with access to Amazon's infrastructure can read anything they like out of the memory of the machine your instance is on without you or anyone else ever knowing it.
- dogma1138 10y agoIf you are worried about actors with that capability you probably want to airgap your entire operation.
- BrainInAJar 10y agoDoesn't need to be airgapped, just defended, and not in the cloud. If the client is someone like Juniper or Cisco (which, if you're a pentest firm buying 8x gpu servers for cracking hashes, would be a reasonable customer) nation state actors would absolutely love to have access to your dataset. And they're already in AWS's datacentres.