4 ms·
Another great example why I love to use managed services / serverless services and not take care of security groups and NACLs
by jack335 5y ago
Another great example why I love to use managed services / serverless services and not take care of security groups and NACLs
- jfkimmes 5y agoInteresting. The conclusion you draw from this differs wildly from my conclusion. Whenever I read stories like these, it seems clear to me that someone moved to the cloud in order to not have to care about security. The 'cloud does everything for you!'. Just like you imply in your answer that PaaS, the next level of abstraction, will solve all your security problems. This move, however, will inevitably lead to a situation where people work with new and complex systems that they don't understand (remember: not having to understand them is the sole reason they use them). Unfortunately, working with complex systems you don't understand is the number one reason for vulnerabilities in the first place. I am not convinced that a service exists that abstracts security away from you.
- sofixa 5y agoThere's another side to this. The people deploying things with a security group open to the internet and no auth might have been saved by a grumpy network admin forcing them to use a VPN or even a firewall, but that's IMHO only hiding the real problem ( security not taken seriously) behind a thin fence. When that fence gets breached, everything would be up for grabs, so the main difference with "the cloud" is that such terrible security postures are easier and faster to spot ( from both sides). Zero trust everything.
- BrandoElFollito 5y agoIt depends which kind of security and which provider. I would trust Microsoft more on patches/configurations for an email system than something which is managed on premises. You need to have really good people to maintain a good level of security. Not only technically good, but also with a string cold management that will force updates even if it means the CEO will not get his maol for 15 minutes - and say that this is life and that the discussion i sover. On top of that, MS would (I hope) install patches on their customer-facing systems in advance of an official patch release. The above applies to the majority of large SaaS services. Now when you have a "Platform", a hoster that requires you to bring in knowledge and not only data then it gets dangerous. You need to maintain the security of what you bring in. This can be an OS (your "Platform" provides VMs), or code (your "Platform" provides code runners). Unfortunately, when a company moves to the cloud, they sometimes forget to do this assessment and end up with monstrosities they installed themselves (which is not different, security wise, from having it on premises - augmente nu the 7B population that potentially has now access)
- notwedtm 5y agoI think the word "managed" is the clear differentiator here. There is a huge difference between setting up ElasticSearch on some EC2 instances yourself, and paying ElasticCo for a managed cluster. I would expect the latter to be sure by default.
- ThrashBeard 5y agoManaged services don't save you from that. You still have to configure security groups to reach them and a lot of devs just use the easiest way and expose the thing to the internet.