6 ms·
Amazon insiders sound alarm over security
- deleted 6y ago[deleted]
- rtrdea 6y agoWe need to re-decentralize the web
- nothasan 6y agoAnd how does this solve the problem of information security?
- throwawaysea 6y agoMoving away from a few megacorps would mean consumers have choice in selecting an alternative provider who takes privacy and security more seriously. Today that choice doesn’t exist because Google, Amazon, Facebook, and other big tech companies don’t face competition either due to a traditional monopoly/oligopoly traits, extreme capital advantages, or network effects.
- Johnny555 6y agoCustomers have the choice to not use Amazon today, but how would you give them visibility into who takes privacy and security more seriously? Is Walmart safer? Target? How about my local retailer that only takes orders by phone and types them into a spreadsheet on a poorly protected computer?
- drivebycomment 6y agoTell me which provider takes security seriously and how you know that.
- maclured 6y agoAn anonymous decentralised marketplace like Amazon is exactly the problem particl [1] is trying to solve. [1] particl.io
- koluna 6y agoNot surprised, considering that they spin every little feature into its own AWS service. it would be an insane task to easily control the data flow, retention policy and anything like that.
- 015a 6y ago> "These inaccurate, unsubstantiated and dated claims don’t reflect our commitment to keeping personal information safe. Amazon has comprehensive, long-established privacy and security policies, procedures and technologies in place. Every company has Policies. Zero companies have Realities which match their policies. This means nothing. > We regularly audit our services to ensure compliance and have zero tolerance for employees at all levels who do not follow our policies," The only people who trust security auditors are people who haven't been through a security audit. Many companies who've been hacked were audited. This means nothing.
- pm90 6y agoWhile security audits are woefully behind the times, they’re not nothing. They do make companies take security seriously, to an extent. The problem with security is that it’s often not enough, you just need one weak spot to break through.
- rualca 6y ago> Every company has Policies. Zero companies have Realities which match their policies. This means nothing. Throughout the years I've grown a dislike of company policies. They feel like a tool designed to discard accountability down the totem pole. An executive asks an underling to write a policy, he publishes the report with or without a revision or care, and from thereon any and all responsibility regarding a problem is automatically circumscribed to the poor entry-level bastard who was forced to something remotely related to the policy.
- nowherebeen 6y agoSomehow I am not surprised given all the talk about toxic culture at Amazon from current and past employees.
- WalterBright 6y agoI personally know a couple ex-Amazon people who thought it was a good place to work and thrived there. Of course, that's not worthy of writing a newspaper article about :-/ I'm not saying it is or it isn't. But ask yourself, which viewpoint sells more newspapers?
- pseudalopex 6y agoThey didn't say they read about it.
- fshbbdssbbgdd 6y agoIt’s odd to see security issues at a company revealed by a whistleblower instead of a breach. Usually I’d expect if an insider working in security notices problems, that’s good for their career because it’s their job to find and fix that stuff. Obviously if it doesn’t work that way at Amazon, that’s a huge problem.
- smaudet 6y agoYeah...this speaks to endemic corruption within the company as well as just a completely rotten management. It is unfortunate but true that with successes come a certain develish breed of human, as well as encouraging some of the worst behavior in otherwise decent folk. Whenever you get a certain level of money involved you can be sure you are dealing with criminals, two bit liars, and psycopaths. Sounds like the mgmt psycos over at amazon have rediscovered the old red tape as a quick way to keep costs down. Just another reason these big biz need proper regulatory oversight, the psychos will still come but at least it should get easier to throw them in a cell when they are discovered.
- ActorNightly 6y agoEvery time I read articles like these, I get dissapointed about the state of the internet. The only thing you know that is likely to be true is that someone got fired from Amazon, and thats it. You don't know if they are telling the truth. You don't know if they were in the right. You don't know if Amazon was fixing the problem, and they decided to be an asshole and go over their bosses because they felt that not enough was being done. You don't know if their actions were compromizing the buisness operations. E.t.c and so on. If you read this and feel like Amazon did something wrong, you are part of the problem. Don't believe anything that ist backed by clearly cited sources. Which that article clearly lacks. But alas, you clicked and scrolled, so as far as politico.eu is concerned, thats all that you needed to do.
- papaf 6y agoThe only thing you know that is likely to be true is that someone got fired from Amazon. From the article: > The warnings about privacy and compliance failures at Amazon come from three former high-level information security employees — one EU-based and two from the U.S. So 3 employees involved with security and not 1 employee. Also, they were pushed out AFTER alerting about security issues.
- ekianjo 6y ago> So 3 employees involved with security and not 1 employee. Also, they were pushed out AFTER alerting about security issues. How much credibility do you put in such testimonies though? Especially if everyone is a "anonymous source", you can basically invent just about anything and publish it and pretend for it to be a genuine article without any fact under the hood.
- ashkankiani 6y agoHow much credibility do you put in Amazon's?
- ActorNightly 6y ago
- vmception 6y agoIts good they are sounding the alarm, for example, Crypto AG had their cryptographer employees continually find security flaws only to have upper management tell them to work on something else, only to find out after 50 years that it was a CIA operation selling backdoored products to nation states. With nothing being outside the realm of possibility, removing the need for trust should be priority number one.
- mike_d 6y ago> Crypto AG had their cryptographer employees continually find security flaws only to have upper management tell them to work on something else I would be very interested if you could share accounts of this happening. From the declassified documents I have studied the Crypto AG "backdoor" consisted of misleading customers that less complex models (with smaller keys) would be suitable for their communications, working with the NSA to word end user documentation in a way that makes it unclear how important specific settings are, and providing technical designs to the NSA for review. At no point do I believe there was a security flaw that an employee would have found that would have compromised the operation, since it was simply a series of steps that weakened the strength of the encryption from "mathematically impossible" to "requires a purpose built supercomputer." This route provided plausible deniability to everyone involved (remember that other cryptographers also evaluated Crypto AG products and would work to secretly exploit any flaws they found "for the bad guys"). Interestingly before the CIA/BND deal, the French attempted to secretly buy the company and do the exact same thing.
- vmception 6y agoThis is a great discussion and not at all my point. I don't care who tried to compromise what, the consumer and along with their data is beholden to multiple masters.
- DocTomoe 6y agoJust in case you did not see this before - there has been a talk about the Crypto AG and some of the background at last year's replacement for the CCCongress: https://media.ccc.de/v/rc3-103955-cryptoleaks https://media.ccc.de/v/rc3-103955-cryptoleaks
- yalogin 6y agoThis level of incompetence is bound to come out and so given the lack of any high profile security fails from Amazon, I am inclined to not believe the article. I hope I am right because they have a lot of data, a lot.
- Narkov 6y ago> Imagine if a company the size of Amazon had a breach? Is it hard to imagine? Does it really matter anymore? There are [non-Amazon] breaches every few years with 100m+ records. It will happen and people will be shocked and outraged and then it will happen again. Wash, rinse, repeat.
- deleted 6y ago[deleted]
- tppiotrowski 6y ago“We had an insecure vulnerability that we knew about for five years," the second former U.S.-based employee said. "That's unacceptable. I mean, we knew about it." In my experience, knowing about a vulnerability and knowing how to fix it are magnitudes of effort apart. Main reason I saw companies avoid fixing vulnerabilities was third party libraries. Third party libraries had switched to a new version of JDK or Node and upgrading production environments carried a lot of risk or would break other libraries. Companies stayed on old versions because they “worked” and eventually were unable to pick up security fixes. It’s one big advantage that startups have over the behemoths. Upgrading dependencies on products with millions of users without breaking anything is one of the most thrilling and rewarding things I’ve ever done.
- ajsharp 6y ago"The quality of the controls that Amazon has in place is appalling. We found hundreds of thousands of accounts where the employee is no longer there but they still have system access..." Yikes. Not exactly confidence-inspiring.
- altacc 6y ago> because Amazon has a poor grasp of what data it has, where it is stored and who has access to it. I see this more and more in companies where microservices have become prevalent but data strategy hasn't kept pace. Data gets decentralized and services end up storing data from other services, leading to duplication and shadow data that is almost impossible to maintain and control. A coherent data strategy is very important but for many companies hasn't been considered until the problem is well established and painful to overcome.