Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, December 21, 2012

Do Govt. Laws Present Undue Risk To Cloud Computing?

(updated 12/12)  There has been a bit of a buzz regarding access to citizen and company data by the U.S government and the associated risks of Cloud computing in that regard.  I’m talking about the recent searches of gMail and Facebook of WikiLeaks supporters.  Paul Carr’s Tech Crunch article  and  David Linthicum’s InfoWorld story refer to these events.  In addition, the New York Times ran a story on secret F.B.I. subpoenas. When you move your data to the cloud, you lose some control over government access to your data during what may (or may not) be a legal search.  I touched briefly on this last year (here), in my article on the Challenges and Risks to Cloud Computing.  For the purposes of this article, I’ll assume your data is still in the US, not a foreign country data center, which poses an entirely different set of risks.

At issue: an individual or business person’s ability to stop an illegal search of their data when law enforcement shows up at your data’s door (that “door” being the door to your cloud provider’s data center).  There is also worry that Fourth Amendment rights will be trampled on because application data has moved to the cloud.  Because your data now lives in a data center, presumably operated outside your company or home, you lose the ability to know when you are being searched, to stop warrantless searches, and to analyze the warrant and validate that the search is, in fact, legal.  Unless you (or preferably your lawyers) are at the data center during the search, you can’t ensure that it adheres to the boundaries set by the warrant to prevent fishing expeditions.  At the same time, you may lose control of privacy or company secrets as part of that search.  How do you protect your Fourth Amendment rights if you don’t even know you are being searched?  If your data is co-located with other individuals or businesses that are being searched, how are you protected from information leakage when they are searched?

Thursday, November 15, 2012

Higher Risk in Data Loss than Security in the Cloud

In this article in InfoWorld, Gartner makes an interesting point.   Data loss is a bigger risk than security in the cloud.   They almost seem to intimate that  businesses using the cloud assume that they don’t need to have a backup and recovery plan if things turn ugly.

 Moving to the cloud doesn’t mean you can quit thinking about business continuity.  Whatever the service, IaaS, PaaS, or SaaS, you still need to understand what the backup and recovery plan is and how the vendor ensures recovery and up to what point in time.

Friday, September 14, 2012

CloudPassage Cloud Security Product Review

Updated:I came across a white paper published by CloudPassage, most likely in the attempt to drive interest in their cloud security product.  It worked, since it resulted in my doing a little digging into their product.  They did bring up a security threat I hadn’t thought of and it was just enticing enough to get me to investigate their offering a little further.  Their paper was focused on Infrastructure as a Service (IaaS) environments like Amazon Web Services (AWS) (reviewed here), or Rackspace (reviewed here).  The CloudPassage paper focused on the security threats within the context of the products that they offer in order to mitigate these threats.

I will review some of the key points made by CloudPassage here, and then I’ll review their solution offering.   Hang on though -- this article assumes you understand cloud IaaS, and some general Linux and security topics.

Thursday, September 13, 2012

Patch Management in the Cloud


I was on my way to a lunch appointment when I started thinking of the headache of managing patching in the cloud.  More importantly how would you ensure that your template server that is used to clone for new servers is current?  

To resolve this, I’d love to see a cloud provider offer the ability to patch the dark VM on disk and if you have a local cloud, say using vmWare, do the same thing to your VM on disk.  After all, there’s an exploit to go directly to a VM image, why not a program that will scan that disk image?

Tuesday, August 14, 2012

Another example of why to use Google’s Two-Factor Authentication


This is a good article on how to close security holes for Google Apps users.  At the core is “two-factor authentication”.  I’ve written about two factor authentication before and I wish it was available on more sites.  I like Google’s and PayPal’s implementation (using my iPhone to receive a one-time second authentication password).  It’s not a huge pain because I can check a box to have Google remember me for a while.  Why aren’t more sites using this?  My bank doesn’t even offer this.  Although two factor authentication isn’t the end all be all of security, it closes a gaping hole.


Saturday, June 11, 2011

Comparing Local to Cloud Security

The first thing that prospective cloud users ask about a new cloud application is "What about security?".  It's a good question, and one that should always be asked when looking at a new public cloud based service vs. internally hosted “private cloud solutions”.  One of the things that I highlight for my clients is that when looking at the security implications of using a public cloud computing service, they should use a fair comparison.  They should compare the security of the public cloud to their alternative, usually an application deployed on their "private cloud" or locally hosted solution, on their own hardware located within their walls.  

This is the first in a series of articles that I will be writing to help answer how we can evaluate cloud security for our business and make good choices.  I want to peel away that first layer when evaluating security.  What you might find is that getting into minute detail on cloud vendor’s security scheme isn’t needed if you can’t afford to do the most basic things for your own locally hosted business system.   I’ll revisit some of the things I mentioned in the security section of my risks article.

Saturday, May 28, 2011

Using Google's Two-Factor Authentication

UPDATE:  If you've read about Gmail account passwords getting stolen (hackers getting users to load a fake page and stealing password) and you are concerned, you really should read this.  Had those users turned on Google’s “Two-Step Verification” they probably wouldn't have been hacked.

Google introduced what's known in the industry as "two-factor authentication” last year.  Google calls it "2-step verification".  Although I use a two-factor authentication system every day for the company I work for and have used others in the past, it’s time to tighten my security belt. In addition, I feel that if I’m going to write about Google’s system, I really should be using it.  Actually I think you should too.  Security is in the news a lot more these days and people are putting more of their lives into the cloud.  If you use Google Docs and other services like I do, you should be doing a better job of ensuring your stuff is secure and private.  

After the break, I’ll explain what it is, how it works, and how to turn it on for your Google account.

Tuesday, April 26, 2011

My Thoughts about Amazon Web Service Failure


Amazon Web Services (AWS) had a major failure last week and there was a lot of buz about it since it took down several major web sites. AWS is one of the leading cloud infrastructure or platform as a service companies. When they fail, it's big news.

Here’s my take.  No solution will provide 100% up-time There will always be a use-case that was not anticipated, failure mode that was not thought of, or human error that couldn’t be mitigated.  Is this a reason to call cloud computing with AWS a failure?  No.  Although I don’t know what their up-time stats are, I’m willing to bet that even if you don’t use multi-site implementation the benefits of scalability, flexibility and up-time still rival what a lot of companies could do on their own for the cost.

Tuesday, June 1, 2010

Challenges & Risks of Implementing Cloud Computing


(Updated 10/25/2011)
After writing about the benefits of cloud computing, I mentioned that it’s not without some risk and downsides. Cloud computing presents a strong case for cost savings, new capabilities, flexibility and speed, but to do a proper return on investment (ROI) analysis, you need to evaluate the risks and costs associated with implementing cloud computing for your organization. This article describes risks and disadvantages of moving to “the cloud,” how to mitigate those risks, and identifies issues relevant to your provider choice and implementation plans. In addition, there are topics that may not qualify as risks or disadvantages of cloud computing, but that may require an assessment of the impact on your organization. An evaluation of the risks and impact is an important precursor to decision-making regarding whether to make the move to “the cloud” and who you select to provide ”cloud” services. In fact, thinking about and addressing these issues should be part of the planning process for any deployment (cloud or not). Critical components of such planning should include technology, personnel, business process and company culture. Moving to “the cloud” requires not only considerable planning, but possible unexpected financial investment.