3 ms·
Poor amazon and microsoft, unable to afford to build their own silicon
by Shebanator 7y ago
Poor amazon and microsoft, unable to afford to build their own silicon
- dogma1138 7y agoThe world isn’t Amazon or Microsoft, and even for them it’s borderline questionable if designing silicon at scale is the best use of their resources at this point. As I’ve stated already it’s the last thing you do when you think about security not the first. When the security posture of your code, configuration, facilities, supply chain etc. is so good that the only attack vector left for adversaries to exploit to compromise your organization in a sufficiently broad manner is the hardware is when you start thinking about building your own silicon. Or when ofc there are actual business needs for this e.g. you want to be independent of other SoC/ASIC designers or there aren’t any solutions that meet your needs. Which also comes to the actual point other than the Google key/hsm solutions that look more of a rebadge than a home grown design Google is focusing on things like the TPU due to business reasons aka $$$ not security. Google isn’t going away from Xeon/EPYC or x86 any time soon, and I find it very questionable if anyone would make a security argument against NVIDIA GPUs as far as Google goes since Google even wrote their own driver stack and CUDA compiler.
- positr0n 7y agoDoesn't AWS make their own NICs to support the security features in their custom network stack?
- dogma1138 7y agoDo they build their on NICs for security or because it’s the cheapest way of segregating network traffic? As in relying on logical separation of client traffic rather than physical one so they don’t need as many physical ports, switches and most importantly network cables(often the highest actual cost in many data centers as far as networking goes)?
- Hikikomori 7y agoYou can get that with vlans. Buying gold plated cables?
- positr0n 7y agoNot at AWS's scale. You can only have 4094 VLANs.
- Hikikomori 7y agoPer switch. Much much more if you use vxlan. My point is that they're not doing it for separation as normal nic's are capable of that.
- dogma1138 7y agoPer LAN not necessarily per switch, overall getting out of the 16bit tag limit takes a lot of work. I’m not sure if anyone actually uses VXLAN yet. You didn’t actually made a point because you haven’t provided proof that what Amazon did for AWS wasn’t done because of operational requirements.
- UlisesAC4 7y agoIntel can afford to do its own silicon and they are not going really well security wise right now. But that was not the message, is about understanding risks.