I was a senior manager on the very first product the article talks about. I was closely involved in designing the service and presenting it to Amazon senior leadership. WSJ quotes the CEO of a startup called DefinedCrowd as accusing us of stealing their ideas from a meeting 4 years earlier. What a bunch of conceit. I don't remember our team discussing DefinedCrowd even once. We focused on the many other more interest…
Amazon met with startups about investing, then launched competing products
321–330 of 385 posts
Re: Amazon met with startups about investing, then launched competing products
#322Earlier quoted context omitted.
The point I’m trying to get across is that the default viewpoint of many knowledgeable developers I know is ‘Of course AWS can’t see inside my EC2 instance because X’ — where X is some magical technology that doesn't exist. I don’t want to devolve into audit logs and permissions and multi user key signing and wether they actually do or not. The statement that ‘they can’t’ is 100% false, full stop. That’s all I’m tryi…
The technology to do it does exist likely on hardware you possess. The trusted computed platform lets you build a signed OS that encrypts its data using keys on the TPM. Using this, you could build an S3 implementation that stores customer data, but doesn’t let you access it. It’s probably not a good idea to make a system with no human fallback, but it IS possible with current, non-magic technology.
Amazon does take privacy and security very seriously, but these systems are run by people. Attacks like the recent Twitter attack could work for various AWS services.
Source: I used to work in EC2 Networking.
Re: Amazon met with startups about investing, then launched competing products
#323Earlier quoted context omitted.
> I can confidently tell you that Amazon's employees cannot see customers data inside S3 buckets or EC2 instances. From a technical standpoint, that statement is false. Every employee might not have the credentials to, but for AWS to function as it does, SOMEONE inside the company has to have those credentials. If you change 'cannot' to 'don't', well then we've just gotta take you at your word, which is where we star…
Except they get audited by 3rd parties on statements like that, and have controls tested. It's not like they're just ... digital ocean or somebody.
Source: Worked at AWS for several years including working on systems that had audit requirements for [secret project where I could not know the name of the customer because I don't have TOP SECRET security clearance].
Re: Amazon met with startups about investing, then launched competing products
#324Re: Amazon met with startups about investing, then launched competing products
#325Earlier quoted context omitted.
> I can confidently tell you that Amazon's employees cannot see customers data inside S3 buckets or EC2 instances. From a technical standpoint, that statement is false. Every employee might not have the credentials to, but for AWS to function as it does, SOMEONE inside the company has to have those credentials. If you change 'cannot' to 'don't', well then we've just gotta take you at your word, which is where we star…
for its faults aws takes data privacy super serious. if you are in support you cant even see attachments customers put on cases without providing auditable justification and you def cant see in s3 buckets or instances. hell if a customer sends you a link to an object in their s3 youre not supposed to open it
Re: Amazon met with startups about investing, then launched competing products
#326Short story: Amazon representative tried to trick influencer into sending their traffic without compensation.
Long story:
At the time, I commercially represented an influencer (largest in a mainstream niche with an active targeted fanbase) who had been approached by Amazon to sell access to our online course on Amazon (as in: let customers buy a coupon code for our content platform). The paperwork we received to sign did not reflect the terms we had negotiated. It included some kind of fees etc. that had never been mentioned, basically shifting percentage in favour of Amazon using fine-print. This felt dishonest.
We decided to do it anyway due to their promises of considerable sales for our program including projections. Then the representative showed us a listing of a direct competitor and told us the number of sales this competitor was able to generate. While it's nice to be on the receiving end of such information, it's unethical. Who knows how truthful the numbers were anyway.
But then the week of deals started and nothing happened. No sales.
This could have had many causes but instead of revisiting the offer or the listing or just say "bad luck", the representative kept insisting that the influencer send their traffic to Amazon which is usually a business transaction but that wasn't part of the deal. They kept insisting anyway, even a second representative.
I'm not keen on doing business with Amazon after that encounter.
Re: Amazon met with startups about investing, then launched competing products
#327Earlier quoted context omitted.
What you say is openly contradictory. They receive certain exemptions due to their size, but their tax bill has nothing to do with their size. ???
No, I said quite clearly there are no exemptions due to their size. There's a difference between an exemption for companies with N+ employees and tax credits/exemptions you can capitalize on because you are a company that makes billions of dollars and can afford to take on different behaviors to take advantage of them. That's not the same thing at all.
Re: Amazon met with startups about investing, then launched competing products
#328"An Amazon spokesman said the company doesn’t use confidential information that companies share with it to build competing products" Maybe...but in the past, AWS proactively looked at traction of products hosted on its platform, built competing products, and then scraped & targeted customer list of those hosted products. In fact, I was on a team in AWS that did exactly that. Why wouldn't their investing arm do the sa…
Cannot up vote this enough. During my time both at Retail and AWS it was perfectly normal to trawl production customer data and come up with ideas to launch competing products. Prices were always set lower or free offering justified as data-driven and customer obsession. I hated the gas lighting their customers and left in disgust of the company and its leadership which encourages that behavior.
Re: Amazon met with startups about investing, then launched competing products
#329Earlier quoted context omitted.
The technology to do it does exist likely on hardware you possess. The trusted computed platform lets you build a signed OS that encrypts its data using keys on the TPM. Using this, you could build an S3 implementation that stores customer data, but doesn’t let you access it. It’s probably not a good idea to make a system with no human fallback, but it IS possible with current, non-magic technology.
The reality is that groups of people inside AWS have access to your stuff. A given person might only be on the S3 or EC2 team... but each of those teams can ssh to hosts in production, or has other access that could be used to compromise your data. Amazon does take privacy and security very seriously, but these systems are run by people. Attacks like the recent Twitter attack could work for various AWS services. Sour…
Re: Amazon met with startups about investing, then launched competing products
#330Isn't this just what you would expect a company of this size to do? "We want to launch a product in category X" "Ok, should we roll it ourselves, or buy something?" "Well, let's interview a few companies, see if there's any we like, and if not, we'll make it ourselves"
A) copy; B) buy; C) sue
you're always violating some patents by IBM and the like, sometimes they don't want to compete with a product only to get you off the table... and sometimes they can do that easily
Oh, and there is the enterprise variation (option D?): talk with the costumers and demand that they stop working with the competition