Live data from Hacker News

Amazon met with startups about investing, then launched competing products

wsj.com

281–290 of 385 posts

Re: Amazon met with startups about investing, then launched competing products

#281

There's no way to really know how true this is but it certainly feels true if you're on the startup side - however most startups just aren't being realistic with themselves, and thinking they are special. For example, my previous company brought our 6DOF MonoSLAM SDK, 3D model processor and OpenGL viewer to Amazon from 2014-2017 pitching the "AR View" functionality that they eventually put in 2017 [1]. Was that a res…

> These big companies aren't dumb, your idea isn't that novel and they probably have the team and technology to do it better than you for cheaper.

This is only partially true. The thing is that even if your idea _is_ novel, giants like AWS can launch a similar product after seeing yours and thats a problem, imo.

Re: Amazon met with startups about investing, then launched competing products

#282

Earlier quoted context omitted.

I'm sorry but what you just said is patently false: https://www.bloomberg.com/news/articles/2019-07-29/capital-o... Quote: Capital One Financial Corp. said data from about 100 million people in the U.S. was illegally accessed after prosecutors accused a Seattle woman identified by Amazon.com Inc. as one of its former cloud service employees of breaking into the bank’s server. While the complaint doesn’t identify the…

My reading of this is that the ex-employee used the knowledge about EC2 instance credentials being accessible as a path to gain unauthorized access to data. In theory anyone could have exploited this vulnerability even if they had never worked for Amazon. They never say that Amazon employees had privileged credentaials that would give them unauthorized access to customer data. AWS customers that want to avoid this vu…

There was zero inside knowledge and they were an ex employee at all times relevant to the incident.

The EC2 instance credentials via the metadata url is public documented functionality. Its how things like the SDK “just work.”

The S3 bucket policy, instance creds, and (inferred) overly permissive IAM policy is all public documented functionality. This looks like a simple case of an initial intrusion being escalated via permissive configuration and controls. There would be no story if the suspect had not been employed by AWS in the past.

Disclaimer: Im a Principal jn AWS but have no direct or inside knowledge of this incident. Everything I know or have stated here is public record (eg the indictment) or public AWS docs.

Re: Amazon met with startups about investing, then launched competing products

#283

Earlier quoted context omitted.

I think perhaps you misunderstand the architecture of KMS. KMS master keys are used to remotely decrypt the symmetric encryption keys for encrypted data that are stored alongside the encrypted data. KMS master keys don't ever leave the KMS servers themselves, and servers can't be accessed directly by anyone. AFAIK they don't have open ports except for handling production traffic and are hardened against opening a she…

I think you misunderstand my concern. What I'm missing in the above scenario is that a resource that should be 100% under the control of the customer and nobody else can be accessed by AWS personnel to open up a door that should be closed unless the customer permits access. What the technical implications are is moot, the process that hands out these credentials should not be accessible to anybody but the customer. I…

some1 with the right access to the kms service could change a key policy to allow access to a bad guy. in theory. bcuz some1 has to have access to key policies since customers lock themselves out of their keys all the time.

but no 1 can export the private key itself. and key policy changes are vry heavily audited by aws (and can be by the customer, too). this is all proven by the 3rd party audits aws receives

Re: Amazon met with startups about investing, then launched competing products

#284

Earlier quoted context omitted.

If you see another employee committing a crime, you're obligated to report it under US law. You can be considered an accessory if you don't.

Attorney here!* That is totally false. Conspiracy requires two elements: an agreement to commit a crime, and an act in furtherance of said crime. There is nothing unlawful about looking the other way. You might be a scumbag, but that's a different problem. The elements of criminal accessory require one to harbor, conceal, or act in such a way as to help someone avoid or escape arrest or punishment (CA law here, other…

We need more attorneys. Attorney saves the day.

Re: Amazon met with startups about investing, then launched competing products

#285

Earlier quoted context omitted.

> I can confidently tell you that Amazon's employees cannot see customers data inside S3 buckets or EC2 instances. From a technical standpoint, that statement is false. Every employee might not have the credentials to, but for AWS to function as it does, SOMEONE inside the company has to have those credentials. If you change 'cannot' to 'don't', well then we've just gotta take you at your word, which is where we star…

> SOMEONE That's not necessary unless SOMEONE includes computer programs. Yes, when things go very seriously wrong, I believe AWS can have literal people override that permission, which will leave a mile long audit trail and likely accompanied by an internet scale outage.

The point I’m trying to get across is that the default viewpoint of many knowledgeable developers I know is ‘Of course AWS can’t see inside my EC2 instance because X’ — where X is some magical technology that doesn't exist.

I don’t want to devolve into audit logs and permissions and multi user key signing and wether they actually do or not.

The statement that ‘they can’t’ is 100% false, full stop. That’s all I’m trying to get across.

Re: Amazon met with startups about investing, then launched competing products

#286

"An Amazon spokesman said the company doesn’t use confidential information that companies share with it to build competing products" Maybe...but in the past, AWS proactively looked at traction of products hosted on its platform, built competing products, and then scraped & targeted customer list of those hosted products. In fact, I was on a team in AWS that did exactly that. Why wouldn't their investing arm do the sa…

I was on a business call with someone from AWS on a different topic, and it was pretty darn clear they opened up some sort of Account page that discussed our (limited) AWS usage, and were trying to infer a bunch about our business from that. It doesn't even really matter how deep that data goes - even just month-over-month billing #'s or something like compute/bandwidth consumption is super telling.

We mostly only do CI type stuff there, so that didn't work so well for them, but if most of our revenue & operational use was through AWS, you bet I'd be worried about what they could infer.

Re: Amazon met with startups about investing, then launched competing products

#287
post #279
post #236

Earlier quoted context omitted.

Whenever anyone asks for evidence I start to wonder why they need the proof. Why did you need this link? Do you have a business relationship with Amazon? https://www.google.com/amp/s/www.wsj.com/amp/articles/amazon...

> Whenever anyone asks for evidence I start to wonder why they need the proof. Why did you need this link? Do you have a business relationship with Amazon? I had made an oath to myself to not return to Hacker News and engage with the community after I was once temporally banned on Hacker News. But when I saw your stupid comment and recognized its disingenuous manipulation and misinformation, a pushing of an evil and…

You last posted posted here just eleven days ago, so that clearly wasn't a very binding oath.

But welcome back I guess.

Re: Amazon met with startups about investing, then launched competing products

#288
post #223

Earlier quoted context omitted.

DO doesn't have a great track record for customer trust. I run personal workload but couldn't recommend it over AWS to a larger company. - https://news.ycombinator.com/item?id=23117660 - https://news.ycombinator.com/item?id=20064169

Sales != Engineering (in regards to the first one), AWS have had similar issues. The second one wasn't good. https://www.zdnet.com/article/aws-error-exposed-godaddy-serv...

There comes a point where your pricing is so opaque and confusing that it's indistinguishable from lying.

Those people are jealous of AWS.

Re: Amazon met with startups about investing, then launched competing products

#289

"An Amazon spokesman said the company doesn’t use confidential information that companies share with it to build competing products" Maybe...but in the past, AWS proactively looked at traction of products hosted on its platform, built competing products, and then scraped & targeted customer list of those hosted products. In fact, I was on a team in AWS that did exactly that. Why wouldn't their investing arm do the sa…

Cannot up vote this enough. During my time both at Retail and AWS it was perfectly normal to trawl production customer data and come up with ideas to launch competing products. Prices were always set lower or free offering justified as data-driven and customer obsession. I hated the gas lighting their customers and left in disgust of the company and its leadership which encourages that behavior.

Stallman was right:

https://www.gnu.org/philosophy/who-does-that-server-really-s...

Re: Amazon met with startups about investing, then launched competing products

#290

Earlier quoted context omitted.

I think perhaps you misunderstand the architecture of KMS. KMS master keys are used to remotely decrypt the symmetric encryption keys for encrypted data that are stored alongside the encrypted data. KMS master keys don't ever leave the KMS servers themselves, and servers can't be accessed directly by anyone. AFAIK they don't have open ports except for handling production traffic and are hardened against opening a she…

I think you misunderstand my concern. What I'm missing in the above scenario is that a resource that should be 100% under the control of the customer and nobody else can be accessed by AWS personnel to open up a door that should be closed unless the customer permits access. What the technical implications are is moot, the process that hands out these credentials should not be accessible to anybody but the customer. I…

I believe youre misunderstanding how KMS works and is exposed. You probably want to look at the concept of “kms grants.” Thoese regulate which principals, including service principals, can use CMK materials. The customer controls those grants. There are also substantial public docs, and more available on request, around the implementation, certification, and compliance of KMS infrastructure. If KMS is insufficient for your needs CloudHSM is availble for something even closer to “hosted HSM” than “key service.”

In short IAM controls everything, there is no “back door” or universal admin access, and KMS is used to perform sensitive operations NOT handing secrets to arbitrary (internal or external) consumers.

Post reply on HN