4 ms·
What makes you think that the big cloud is somehow more security-conscious? Because they said so?
by dgudkov 3y ago
What makes you think that the big cloud is somehow more security-conscious? Because they said so?
- closeparen 3y agoThe major cloud providers are serious engineering shops whose business and reputation actually depend on technical and operational competence. And the Silicon Valley community is full of current and former employees who will tell you what it's like inside.
- csydas 3y agoAt some level in the infrastructure this may be true, but this is not my experience working directly with the RND/Engineering teams and Infrastructure teams on a lot of the big cloud providers. They will undoubtedly have many tricks to get whatever you have on their cloud working again, but there should not be an expectation that they aren't going to just get a fast and dirty fix going. It might work, but it will be a kludge in many cases. Same with security; quite a few of the S3 on-premises providers have backdoors that allow a person to bypass even the S3 immutable functions -- while I can understand that for specific customers who are using the S3 infra for Storage as a Service needing a way to clean up data from customers who left, such features are not advertised, and IMO, such S3 vendors should not be allowed to call their product "immutable", as it's anything but and most clients wouldn't even know about such backdoors. The actual tech behind the providers might be pretty nice (this is arguable though...), but I would not say that this has any bearing on their trustworthiness as a provider.
- dgudkov 3y agoIn reality, their business and reputation don't depend on security mishaps, because they are too big to fail. See this fresh thread: https://news.ycombinator.com/item?id=37702095 https://news.ycombinator.com/item?id=37702095
- closeparen 3y agoNobody wins every single time against the most sophisticated attackers in the world. Microsoft put up a very respectable fight here. When a random small-to-medium enterprise IT department gets owned, it’s for some braindead stupid low-hanging-fruit reason. Attacks like this don’t happen because they are unnecessary.
- dgudkov 3y agoThere was no respectable fight. They used the same signing key for all customers AND own corporate mail. It's a stupid rookie mistake. Exactly the type you would expect from a small-to-medium IT department.