3 ms·
This is such a ridiculously primitive view of the world it beggars belief. By taking this view you are significantly reducing your security posture, no improvin
by GrimRe 6y ago
This is such a ridiculously primitive view of the world it beggars belief. By taking this view you are significantly reducing your security posture, no improving it.
There is an AWS Region in Germany. Your data will stay in Germany unless you specifically decide to move it elsewhere.
AWS also provide you with the tools to encrypt everything and if done correctly means that Amazon no matter how "evil" they are cannot decrypt the data. Not only that, there is such a huge separation in access and rigour around governance that there is no way anyone within Amazon can simply login and see your data even if unencrypted.
Every single case of data being leaked from AWS is because the people working for the company that manage the data literally checked a box to make the contents public. Contrast this to "on-prem" where physical security can get compromised or the vendors of the physical hardware/software leave gaping holes or maintenance backdoors that get exploited.
Honestly these types of views are no more grounded in reality that flat earth conspiracy type views.
- catmanjan 6y ago>Your data will stay in Germany unless you specifically decide to move it elsewhere. Prove it
- fluffything 6y agoAlso, what happens if you find a leak? Or that it has been moved somewhere else? They say "We are sorry", give you some free credit, and that's it ?
- jacobush 6y agoNo, that won't happen. "Sorry not sorry" and no credit.
- GrimRe 6y agoWhy don't I prove the earth isn't flat while I'm at it? Oh wait, I can't. I guess you win. Clearly my inability to prove the earth isn't flat means that it is flat. See how ridiculous you sound? You think that 25,000+ employees that work at AWS have somehow been silenced into some grand conspiracy? The underlying architecture of an AWS Region is fundamentally designed to keep data in the Region you specify. There is no physical way for it to move between Regions without you specifically logging in and telling it do so. Not only that its extremely expensive to move that data around. You pay for this in Region to Region transfer costs. Believe me AWS would not want this happening for free. That brings me to my other point: AWS don't give a flying fuck about your your boring corporate data either by the way. What they really want is to replace your old expensive insecure data centre hosting shitware like SAP. If you think AWS are secretly peering into your data to make the Amazon global cabal more powerful then you may as well unplug your datacenter and go back to the Stone Age. It'd be FAR easier for AWS to simply exploit some security vulnerabilities is your decades old, half-baked piecemeal built datacenter and syphon intelligence that way than it would be to try and attack their own cloud services.
- reallydontask 6y ago> You think that 25,000+ employees that work at AWS have somehow been silenced into some grand conspiracy? You seem to suggest that every single employee that works at AWS is aware of everything that goes on with the company. Isn't just possible that despite of what we know about the architecture, this might not be the whole truth and concerns about involuntary inter region transfers might just be warranted?
- PeterStuer 6y agoThe arrangements brought to light through amongst others the Snowdon files did involve extremely few people at huge companies. We are talking a literal hand full, not '25.000'. Are you really suggesting there are no three letter acronym operators embedded into the large US tech companies? Modern US systemic tech industrial espionage was brought to light as far back as Echelon. so deriding people who are cautious about it as 'flat earthers' seems disingenuous.
- CyanBird 6y agoYour innocence is quite charming, specially in a post-snowden world
- msh 6y agoHow do you prove that a german company does not have secret data sharing agreements? Think cryptoAG.
- throwaway2048 6y agoI think its much more likely that an American company with a former NSA head as a board member is much more likely to have an agreement like that, personally.
- blub 6y agoYour fancy view of the world is not as fancy as you think and your aggressive, disrespectful rhetoric is doing you a disservice. The measures you've enumerated (EU zones, encryption, etc) are mitigations for working with a potentially compromised vendor and should be done anyway. Not using the vendor is such a blindingly obvious countermeasure that one has to be either unprofessional or have a hidden interest to dismiss out of hand.
- therealdraco 6y agoShut the fuck up and go sit in that corner: there is no honor in humility. A gold hacker knows a feeble wannabe who is here to make friends. If you want a friend, get a cocker spaniel. You ass kissing Java but kissing assholes, with the hacker ness karma And my ycombinator súper scanner for un semantic web? But I knew RUST YOU GUIIISEEEE
- paganel 6y ago> there is such a huge separation in access and rigour around governance that there is no way anyone within Amazon can simply login and see your data even if unencrypted. I personally choose not to believe a company which puts on its board of directors a well-known perjurer [1]. [1] https://www.theguardian.com/commentisfree/2013/sep/25/nsa-reform-fire-officials-lied https://www.theguardian.com/commentisfree/2013/sep/25/nsa-re...
- puszczyk 6y agoWhich companies do you believe?
- paganel 6y agoWe were talking about Amazon here, that discussion probably merits another thread. But yes, I do believe more in companies that don’t bring in ex-government crooks on their board of directors.
- raxxorrax 6y agoDon't forget the mass surveillance of his old job. Even if he didn't lie, you might want to think of hiring him for your cloud services.
- hobofan 6y agoMy bigger worry would be continued data access. So even if the data is in Germany, access to it is still controlled by an US entity, which can be forced by the US government to shut off access. Given that the current administration seems to enact embargos on a whim, this doesn't seem too unlikely.
- cb504 6y agoIn my limited experience, Germans are more sensitive to personal privacy than other Europeans, even the rest of the world. To non-Germans they might seem paranoid. Maybe we can all learn from their historical mistake. The problem I see with the DIY-attitude is that security is easy to get wrong and is moving target. The other opinion here is "keep it in the country". If someone really wants your data, the locale won't save you. And yet, if there is a breach, I could see an foreign company like AWS trying to hush it, where a German company would make a bigger fuss (diplomatic issue).
- LargoLasskhyfv 6y agoHmm, mumble mumble mirrored switch port in the exchange mumble mumble mumble...