3 ms·
By the same token, if I were in Amazon's position, if I were to use the data, I'd make sure nobody knew about it. However, I'd then be in the unenviable positi
by firebird84 9y ago
By the same token, if I were in Amazon's position, if I were to use the data, I'd make sure nobody knew about it. However, I'd then be in the unenviable position of the Enigma codebreakers, attempting to use information without the enemy knowing I had it.
- Touche 9y agoWhy would they take the risk to find out information about a competitor that they are destroying?
- Spooky23 9y agoBecause knowing when and where a trainload of toilet paper is showing up at Walmart gives Amazon stronger bargaining power and ability to hurt Walmart. If they can add a penny to the earnings or take one away from Walmart, that means bonus and stock $$$.
- jxi 9y agoThe same reason you would want to find out information about a competitor you aren't destroying? Just because you're ahead doesn't mean you should rest on your laurels.
- jxi 9y agoThe same reason you would want to find out information about a competitor you aren't destroying? Just because you're ahead doesn't mean you should rest on your laurels.
- Johnny555 9y agoAnd also puts them in the impossible position of having enough top-notch Xen developers that can code a Xen data interception module that runs in the hypervisor to snoop traffic in real-time from instances, while at the same time, expecting this team to keep quiet about it while also making sure that no other team members who aren't "in the know" don't stumble upon the spying code and reveal it. They have to snoop the data from the hypervisor since the only place it's available decrypted is on the virtual machine processing the data.
- CaptSpify 9y agoForgive me as I don't know xen that well, but... Couldn't they just make a copy of the vm, isolate it, and then break into that one? sure the data will be "old", but not by a lot, and it would theoretically be undetectable.
- Johnny555 9y agoThat only gives them the data that's in-flight and already decrypted for processing, but any security conscious company will have their data segmented into many sections that are broken up into smaller pieces with their contents encrypted separately with a decryption key that's stored in a hardware HSM. If they want to capture the entire data stream, they'll need to capture it in real-time.
- CaptSpify 9y agoA) I think you way overestimate the security practices of most companies. I have no knowledge of WM's practices. B) That's likely still going to be a large amount of very usable data
- Johnny555 9y agoHaving worked at a bank that was moving some workloads to the cloud, I don't think I'm underestimating the security practices of companies that consider their company data to be valuable. In the application I was working on, they had over a TB of data, broken up into 32MB blocks, each with a unique key that had to be unwrapped by the HSM. If you stole the VM you'd get only a few blocks of readable data with it. I assume that if Walmart values this data, they'll take similar precautions in the cloud.
- CaptSpify 9y agoI'm not saying that there aren't companies that are responsible with their data. I'm saying I really disbelieve that the majority of companies treat their data this way. There's too many fly-by-night shops. My point though, is that the attack is definitely feasible. I think WM has every right to be concerned.