4 ms·
If security is important to you (and I think it should be) the problem with outsourcing your technology to a company like Microsoft, Google, Amazon or whatever
by nonrandomstring 2y ago
If security is important to you (and I think it should be) the problem
with outsourcing your technology to a company like Microsoft, Google,
Amazon or whatever is that you've no means of really testing it.
This could have gone unnoticed for years as so many cloud provider
gaffes do. It's unlikely that anyone would think "Hey let's try brute
forcing the login today". This violates trust-but-verify. You accept
their say-so and so you're fully delegating trust. And because you're
paying thousands of bucks for a service you assume it must be good.
That's the very model of a (con)fidence trick. You don't even know you
bought a lemon until its too late.
There's no substitute for having someone qualified and educated in
cybersecurity with that as their full-time job - and better yet bring
your critical assets back on-prem with some kind of hybrid setup. Big
cloud is really eating at the McDonalds of cybsersecurity.
- SvenL 2y agoDoesn’t this just shift the problem? From trusting a company it knows about security to trusting ONE person she/he knows about security? I would rather trust a company with x persons working on security than one person. Yes Big Company Microsoft got this one wrong (and also some other), but how many did they right? It’s always easy to be mad at failure if we overlook the times where something was done right.
- nonrandomstring 2y ago> Doesn't this just shift the problem? No. Perhaps counter-intuitively the "problem" isn't trust here. What I'm raising above is not the necessity to trust but the extent to which verification is possible or frustrated. For example, with open versus proprietary code you may or may not have the capacity to audit it, but you always have the possibility. > I would rather trust a company with x persons Trustworthiness does not scale in this way. Though the "many eyes" theory has some weight, we also say "two people can keep a secret if one of them is dead." Assigning more cooks to the broth yields rapidly diminishing returns for reasons Fred Brooks explains [0]. But that is not my strongest objection. A more serious reason not to trust a BigTech company with your security is the "principal agent problem" [1]. As Ross Anderson puts it; "If Alice guards a system and Bob pays the cost of failure, you can expect trouble!" [2]. Microsoft does not "pay the price". Worse, Google (and Meta, Linked-In etc) base their business model on your insecurity - they are primarily in the business of acquiring data about you to use in selling your person to advertisers. They are therefore motivated, however weakly, against your actual security. It's a scandal that such companies also act as data processors and suppliers of services like online storage. So while you can outsource trust, you cannot unload responsibility to verify. A solution is education based on a credo of "principles not products" [4]. [0] https://en.wikipedia.org/wiki/The_Mythical_Man-Month https://en.wikipedia.org/wiki/The_Mythical_Man-Month [1] https://en.wikipedia.org/wiki/Principal-agent_problem https://en.wikipedia.org/wiki/Principal-agent_problem [2] https://www.csail.mit.edu/news/dertouzos-distinguished-lecture-prof-ross-anderson https://www.csail.mit.edu/news/dertouzos-distinguished-lectu... [3] https://techrights.org/n/2024/09/25/Technology_rights_or_responsibilities.shtml https://techrights.org/n/2024/09/25/Technology_rights_or_res... [4] https://cybershow.uk/blog/posts/principles https://cybershow.uk/blog/posts/principles
- netcoyote 2y ago> This could have gone unnoticed for years as so many cloud provider gaffes do. I think that Microsoft is getting away easy here with Oasis publishing the vulnerability report. If Microsoft published the report it would be incumbent upon them to include information about what they did to discover whether this happened before Oasis reported the problem. One wonders how many Azure accounts might have been compromised and are even now allowing data to be exfiltrated.