16 ms·
> The is absolutely no veil between the hypervisor and the guest virtual machines. Not in the EBS either. This is 100% true. To do any useful computation on yo
by TimSchumann 6y ago
> The is absolutely no veil between the hypervisor and the guest virtual machines. Not in the EBS either.
This is 100% true. To do any useful computation on your data (read, what you're using all AWS for) they have to have 100% visibility into your data.
> If they say they won't read your data, better trust them. If you don't, stay away from their datacenters.
That's it, right there. All of this is based on Trust in Amazon, not some technology that provides any assurances, much less proof, they're not looking at your data.
They can pull the curtain off anything you're running in their cloud, at any time they feel like it. It has to work this way for AWS to be of any use, and by using AWS you're implicitly trusting Amazon with your data.
- xnyan 6y agoFor about half a billion they will build you an aws on site(s) you control: https://cloudcheckr.com/cloud-security/understanding-aws-govcloud-aws-secret-region-and-aws-top-secret-region/ https://cloudcheckr.com/cloud-security/understanding-aws-gov...
- darkerside 6y agoThis is a similar level of trust that you give to banks not to seize your money, or to your bodyguard not to do you physical harm. Stealing data from a customer paying for hosting would be _very_ different, and much more scandalous, than identifying trends on a competitive marketplace and taking advantage of them by launching competing products.
- adrianmonk 6y agoOr your commercial landlord to not send the cleaning staff to rummage around in your filing cabinets. Which, while it could happen, is something that people don't really seem to get concerned about.
- calimac 6y agoExactly!!
- werber 6y agoI have been chastised for not locking my desk for this exact concern. It does happen
- milesvp 6y agoDon’t let anyone chastise you for this. Most desk locks are easy to pick. Also, there are like 3 keys to have on your keychain to open like 80% of all manufactured locks like the ones in furniture. Deviant Ulam, a pen tester, gives a lot of talks on this topic.
- renewiltord 6y agoNot really wrong, actually. A friend picked a desk lock for another when they left their charger in there.
- jaywalk 6y agoMost "crimes" of this sort would be stopped by simply locking the drawer. Nobody believes that a simple desk lock would keep out a determined attacker.
- werber 6y agoI pick my battles, I’m not going to complain about a policy unless I think it could really hurt people. If I complained about everything i think is dumb, I’d never be able to keep a job, because most of it seems dumb to me.
- jlbnjmn 6y agoSo true, so often.
- sfifs 6y agoNo the reason for these types of structures is simply to prevent passive leaks of information which is a far more common occurrence. Any large business is frequently visited by vendors and agencies who also work with others in the industry. Similarly, if you're presenting externally, it's a good idea to close open applications that are not relevant to prevent info leaks from Alt-Tabbing. Actually having a competitor pay someone to come into your office to pick locks etc. is rare, comes with criminal liability and is easily detectable on security cameras.
- pacala 6y agoHow about snooping the traffic through a load balancer service managed by AWS? That's exactly 'identifying trends on a competitive marketplace and taking advantage of them by launching competing product', except that instead of looking at sales data of products on your shelves, you look at URL access patterns for sites hosted on your platform.
- TimSchumann 6y agoI don't disagree with any of what you've said. I just think that many people are ignorant of that being the case with Amazon, Facebook, Google, etc because they assume 'Well Technology must have solved that'. Then again, compared to the average bear, maybe I'm unusually circumspect when it comes to all of those things.
- ngneer 6y agoTechnology alone cannot solve the use of technology to promote interests of parties in a zero sum game.
- kortilla 6y agoThe promise of homomorphic encryption is to allow cloud computing without giving your data away.
- pixl97 6y agoWithout giving what data away, exactly? If for example I'm fully on amazon AWS for everything, DNS/DB/Web then no matter how encrypted your data is Amazon still has a very good idea of the effectiveness of your campaign. You can't hide the number of DNS queries. You can't hide the number of TCP SYNs. Hell, there is just a huge amount of things that encryption does not cover up, especially involving time for particular transactions to occur.
- kortilla 6y agoDon’t be obtuse. Observing some encrypted traffic going in and out gives away some info, but it’s nothing like the email addresses, addresses, names, and order history of all of your customers. Amazon, if they wanted, could read stats from Netflix’s database about which movies drive the most engagement and use that to determine what to license for Prime video. It’s the difference between root on the server and capturing encrypted packets on a network.
- hammock 6y agoBanks mightn't seize your money. They certainly take the data from your bank accounts and monetize/resell it. This is a dirty secret, and pervasive. How else do you think "closed-loop" measurement of marketing effectiveness, and retargeting based on purchase behavior are done? How else do you think suppliers can pull a D&B report on your company showing your bank account balances?
- mulmen 6y agoBanks definitely seize your money. When I was a young teenager my parents encouraged me to put my lawn mowing money in a bank account. I had a total of $100.00! We went over to Bank of America and I opened up an account and deposited my hard earned cash. A month or two later I tried to withdraw some cash and was told I had no money. My full $100.00 had been consumed by insufficient balance fees. A valuable if painful lesson to learn. I still do all my personal banking with a credit union and consider my relationship with banks to be adversarial. They only own my debt, never my cash.
- magnetic 6y ago> A month or two later I tried to withdraw some cash and was told I had no money. My full $100.00 had been consumed by insufficient balance fees. Is that an exaggeration? It amounts to $100 or $50 a month in "low balance fee"! All the banks I've looked at had a fee under $10.
- mulmen 6y agoI think it may have been more than a couple of months, IIRC the fee was $20.00. This was a very long time ago.
- pixl97 6y agoThis is like saying Amazon seizes your money because you have to pay for their monthly service fees you agreed to when signing up for the service.
- minikites 6y ago>This is a similar level of trust that you give to banks not to seize your money How many PayPal horror stories have there been?
- derriz 6y agoFor me it's not at a similar level. For one, banks are far more regulated than Amazon is. If governments funded departments with 10s or 100s of thousands of employees monitoring and regulating cloud computing services, then it might be similar. But the most significant difference is that if the bank seizes my money, I'll know about it pretty quickly and can respond. If Amazon sniffs through my commercial data, I'm unlikely to ever know. Most people are far more tempted to do wrong if they know if the chances of getting caught are miniscule.
- nwallin 6y agoIf a bank were to seize your money, you'd notice, because you wouldn't have that money anymore. And it would be very well documented, leaving a clear paper trail to a criminal conviction and a civil suit. If your bodyguard did you physical harm, you'd notice, because your knees would hurt. And there would be ample evidence for a criminal case. If amazon copied all your proprietary data, you would almost certainly never notice, no criminal law would apply, and you'd have a hell of a time proving it in a civil suit. It's the difference between breaking into a Walmart with a ski mask and assault rifle and stealing a bunch of blu rays vs recording the HDMI out from whatever device you stream Netflix from. They're not the same thing at all, either in terms of harm done, applicable criminal law, or ability to build a compelling civil lawsuit.
- darkerside 6y agoYou're right that they are different, but maybe not as different as you think they are. > If amazon copied all your proprietary data, you would almost certainly never notice, no criminal law would apply, and you'd have a hell of a time proving it in a civil suit. If Amazon were doing this and profiting from it, that would essentially be a criminal conspiracy that reaches to the leadership of the company. Is it possible? Sure. Is it likely? I tend to think conspiracy theories are rarely true. Would it be caught? I believe it would likely be caught. Companies get things done by having meetings, informing their hierarchy, and following executive decisions. In what meeting do you imagine this being discussed? Who floats this idea, and who signs off on it? I just don't see it happening. And if it does, I expect whistleblowers to put a stop to it.
- nieve 6y agoCriminal conspiracies by corporate execs are not all uncommon in the history of business and presuming that you can't possibly run into one because you personally haven't is taking an unnecessary risk. One thing due diligence is supposed to look for is criminal behavior. This is not because they never find it.
- reaperducer 6y ago
- kortilla 6y agoBad analogy, I can tell when the bank seizes my money.
- dathinab 6y agoActually it's not _that_ uncommon for guards to be involved into the business of braking in into high profit buildings. At least in countries with partially undermined police/law systems. Which sadly applies to most countries of the world even first world countries where people normally don't think about it.
- kerkeslager 6y ago> This is a similar level of trust that you give to banks not to seize your money, or to your bodyguard not to do you physical harm. That's not true. I surely don't trust banks, but at least they're regulated to the point that they have to come up with some legal pretense for seizing my funds. A bodyguard is ostensibly a person who I've incentivized more than the competition to not harm me, and who I probably form a relationship with over time. None of these things are true of Amazon. > Stealing data from a customer paying for hosting would be _very_ different, and much more scandalous, than identifying trends on a competitive marketplace and taking advantage of them by launching competing products. What part of using data that you have on your competitors but they don't have on you, to sell competing products on a platform where you don't have to pay fees but they do, sounds like a competitive marketplace?
- deliriouspuppet 6y ago> To do any useful computation on your data (read, what you're using all AWS for) they have to have 100% visibility into your data. This is true, but it doesn't have to be this way [1]. [1] https://en.wikipedia.org/wiki/Homomorphic_encryption https://en.wikipedia.org/wiki/Homomorphic_encryption
- pvarangot 6y agoThat would increase their computation costs by a fair bit, it would be more expensive to run the same amount of computation on their cloud using fully homomorphic encryption, even without taking the engineering costs on your side into account.
- TimSchumann 6y agoI'm aware, but thanks for posting nevertheless. I've actually read Gentry's thesis. Last I looked into FHE though it was something like 14 times to 100 times as inefficient (either in time or space depending on the scheme) as operating on unencrypted data. Now things may have changed since then, but I'd imagine it's not yet gotten down to 1.X inefficiency multiplier regardless of the FHE scheme you're using.
- AgentME 6y agoIf AWS used Intel SGX, then it would be possible for them to offer VMs that ran inside of a secure enclave that AWS could not peer into as long as Intel didn't give them a backdoor. (Well, it seems like SGX is insecure right now with all of the CPU vulnerabilities, but in principle it may be fixed in a future generation and be well-suited for this.) The fact that you wouldn't have to trust your host specifically could have a real decentralizing effect for cloud hosting: people would be able to run stuff on any cloud host without needing to trust them much. If you just wanted compute power and didn't care about strong uptime/connectivity, you could even safely rent cheap VMs on computers of random individuals.
- lima 6y agoSGX has no syscalls. You cannot run VMs or any regular application in SGX. AMD SEV, on the other hand, is exactly that.