4 ms·
It has been 0 days since GCP has taken down a startup (again). You see this at least once a year. Never heard of this from AWS or Azure. In all seriousness, t
by dangoodmanUT 5mo ago
It has been 0 days since GCP has taken down a startup (again).
You see this at least once a year. Never heard of this from AWS or Azure.
In all seriousness, this is why we don't use them. They have the most ergonomic cloud of the big three, then absolutely murder it by having this kind of reputation.
- rozap 5mo agoYep, we also don't touch them for this same reason.
- tjpnz 5mo agoAWS normally contacts you first.
- cherioo 5mo agoThey better do. What is google doing?
- Gigachad 5mo agoIt's all AI powered
- kevin_nisbet 5mo agoDo they? The only anecdotal thing I've seen is we hired a vendor to do a pentest a few years ago, and they setup some stuff in an AWS account and that account got totally yeeted out of existence by AWS if memory serves.
- alchemism 5mo agoI’m fairly certain you are supposed to contact any vendor before attempting to penetrate hosts with authorization, not the other way around.
- coredog64 5mo agoHaving done this for both Azure and AWS, there's a specific ticket that needs to be filed with each provider that documents the scope of your pen test, where you're coming from, and a time frame over which you're doing it (which ISTR was "not more than 24 hours")
- mixdup 5mo agoResponding to an unknown security tester like that is a selling point, not a cautionary tale
- kevin_nisbet 5mo agoYup, I thought it was great. Although one concern I always had in the back of my mind was where is the line drawn. Such as if an adversary gains access to one of my orgs accounts and does something similar, do we get 100% taken out.
- dannyw 5mo agoYou should not be conducting unauthorized penetration tests against third party infrastructure providers without permission. They have processes and systems and usually just wants a heads up of what you plan to test and t the duration / timestamps. Cuz otherwise you look like a threat actor. That’s assuming your vendor was pentesting AWS systems. If you meant you hired a vendor to pentest your own systems on AWS, that’s of course a totally different matter.
- kevin_nisbet 5mo ago>That’s assuming your vendor was pentesting AWS systems. If you meant you hired a vendor to pentest your own systems on AWS, that’s of course a totally different matter. Sorry for being unclear, the vendor was attacking our organization only, and any other company was expressly forbidden in the contract. As I recall it was a fake SSO sign-in page to collect credentials that they would try and social engineer our employees with.
- Shank 5mo agoAt a minimum you should contact AWS before you launch a phishing page as a test that targets AWS customers.
- Lukas_Skywalker 5mo agoI understood it as a phishing page imitating their own system, targeting their own employees. Nothing related to AWS, except for being hosted there.
- deleted 5mo ago[deleted]
- raverbashing 5mo agoIf a vendor doesn't know the basics about pentesting open infra and can't be bothered to look up terms of use sounds like they know ssh-it about fsck
- abrookewood 5mo agoYep, agree 100%. Such a stupid move on their behalf.
- jameson 5mo agoWhat was the reason GCP took down a startup previously?
- deleted 5mo ago[deleted]
- __s 5mo agohn.algolia.com gcp blocked https://news.ycombinator.com/item?id=46731498 https://news.ycombinator.com/item?id=46731498 https://news.ycombinator.com/item?id=33360416 https://news.ycombinator.com/item?id=33360416 Then I recall https://news.ycombinator.com/item?id=45798827 https://news.ycombinator.com/item?id=45798827 https://news.ycombinator.com/item?id=33737577 https://news.ycombinator.com/item?id=33737577
- jameson 5mo agoWow... Just wow...
- somewhatgoated 5mo agoOn the other hand i can’t remember when there was a serious outage on GCP, unlike AWS/Azure who seem to go down catastrophically a couple of times per year.
- corpoposter 5mo agoIIRC the Paris datacenter flood took down a whole “region” and some data was permanently unrecoverable.
- JoRyGu 5mo agoAWS goes down catastrophically but are back up in minutes/hours most of the time (as long as they aren't down because Iran blew up their data center). That's obviously REALLY bad for certain industries, but I suspect for the vast majority of their customers it's not a big deal. We've been able to isolate the damage almost every time just by having AZ failover in place and avoiding us-east-1 where we can.
- ajross 5mo ago> AWS goes down catastrophically but are back up in minutes/hours most of the time The outage in the linked article appears to have been resolved in 4-5 hours.
- graemep 5mo agoFailover is supposed to protect you every time, unless something really exceptional happens. While its possible to to isolate the effects, judging by how many things stop working when there is an AWS failure a lot of people fail to do that. I think the shit of responsibility to AWS removes the incentive to put effort into resilience against AWS failure.
- pixl97 5mo agoGCP never goes down because they banned all their customers.
- somewhatgoated 5mo ago
- overfeed 5mo ago> Never heard of this from AWS or Azure. AWS does it more efficiently; it takes down many startups at a time when us-east-1 goes down.
- stingraycharles 5mo agoThat’s an entirely different type of problem, and avoidable by just using us-east-2 (I still don’t understand why people default to us-east-1 unless they require some highly specific services).
- MattGaiser 5mo agoSympathy. Railway is going to have numerous people blaming them for this outage. When us-east-1 fails, it is headline news, so you are not to blame.
- aloha2436 5mo agoIs it that easily avoidable? A lot of AWS's control plane seems to have dependencies on us-east-1, or at least that's what it's looked like as a non-us-east-1 user during recent outages.
- happymellon 5mo agoI don't know how much it's improved, but a bunch of URLs they use unnecessarily have region specific details in them. I remember a Workspaces outage about 5 or 6 years ago, and the problem for us was that the redirect link in the console had US East 1 in it. The workspaces themselves weren't in US East 1 and nothing relied on US East 1. Emailing users who needed it an alternative link with a different region in the URL for the login redirect fixed it for us.
- mgfist 5mo agoAnd we all celebrate it since we can't do any work
- yandie 5mo agoDuring my 5 years of my startup, we had only 1 outage due to AWS because we picked us-west-2 as the primary reason. If anyone starting a company and picks us-east-1 as the primary reason, they should be fired. There's absolutely no reason to be in that region.
- busterarm 5mo agoHetzner and OVH also do this all the time. It's AWS and Azure that are the outliers and tend not to care too much what their customers do with their infrastructure. AWS is perfectly fine with allowing me to run copies of 15 year old vulnerable AMIs copied from AMIs they've long since deprecated and removed. Even for removed features like NAT AMIs.
- Spooky23 5mo agohttps://en.wikipedia.org/wiki/Timeline_of_Amazon_Web_Services https://en.wikipedia.org/wiki/Timeline_of_Amazon_Web_Service... Azure nerfed the front door of all Azure and O365 services last year. All of these companies are great at what they did, and occasionally fuck up.
- OsrsNeedsf2P 5mo agoAWS has throttled our service so badly that we couldn't operate. I was thinking of writing a blog post about how they stalled our growth for a month but it seems moot