Live data from Hacker News

Former NSA chief Keith Alexander has joined Amazon’s board of directors

theverge.com

151–160 of 465 posts

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#151
post #141

Here in Germany I used to work for a company that swore off Amazon and other US cloud vendors because of things like this: the relationships between them and the government are too tight. They didn’t want German user data being compromised. It could have been FUD to do things on premises or what not but it seemed to make sense at the time and now with this...

This is such a ridiculously primitive view of the world it beggars belief. By taking this view you are significantly reducing your security posture, no improving it. There is an AWS Region in Germany. Your data will stay in Germany unless you specifically decide to move it elsewhere. AWS also provide you with the tools to encrypt everything and if done correctly means that Amazon no matter how "evil" they are cannot…

Your fancy view of the world is not as fancy as you think and your aggressive, disrespectful rhetoric is doing you a disservice.

The measures you've enumerated (EU zones, encryption, etc) are mitigations for working with a potentially compromised vendor and should be done anyway. Not using the vendor is such a blindingly obvious countermeasure that one has to be either unprofessional or have a hidden interest to dismiss out of hand.

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#152
post #141

Here in Germany I used to work for a company that swore off Amazon and other US cloud vendors because of things like this: the relationships between them and the government are too tight. They didn’t want German user data being compromised. It could have been FUD to do things on premises or what not but it seemed to make sense at the time and now with this...

This is such a ridiculously primitive view of the world it beggars belief. By taking this view you are significantly reducing your security posture, no improving it. There is an AWS Region in Germany. Your data will stay in Germany unless you specifically decide to move it elsewhere. AWS also provide you with the tools to encrypt everything and if done correctly means that Amazon no matter how "evil" they are cannot…

> there is such a huge separation in access and rigour around governance that there is no way anyone within Amazon can simply login and see your data even if unencrypted.

I personally choose not to believe a company which puts on its board of directors a well-known perjurer [1].

[1] https://www.theguardian.com/commentisfree/2013/sep/25/nsa-re...

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#153
post #125

Earlier quoted context omitted.

Exactly. I'm constantly surprised how many companies carelessly upload all their internal documents to Google Docs, S3, Dropbox, GitHub, Slack et al. I'd suggest that anything that's not supposed to be public never be uploaded to such services, specially if you are not from the US. The way to go even for small tech companies is self hosting, except maybe for email, due to GMail marking your emails as spam from what I…

I think you’re really overestimating the ability of most small tech companies to self-host reliably and securely.

You’d be surprised. We had security that rivaled even the standards required by the banks. Truly crazy high multiple physical key paired with vault and some faraday cage protected offline signing thing — I wasn’t privy to it all just saw bits of it while it was being implemented. Suffice to say it can be done and by going off cloud you get the flexibility to do things like this but... in the end it’s overkill

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#154

Earlier quoted context omitted.

I'm not devops, but how hard is it to properly set up VPN / ssh ? We have a gitlab server, and connecting requires being on VPN, which requires 2FA, and then ssh, which requires your keys to be properly set up.

Parent comment is talking about self hosting “Google Docs, S3, Dropbox, GitHub, Slack“. Running all those things (and more) instead of focusing on your core business is probably a mistake for most companies.

Ah, gotcha, agree that makes no sense. We only self-host gitlab and zulip.

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#155

Earlier quoted context omitted.

I think you’re really overestimating the ability of most small tech companies to self-host reliably and securely.

You’d be surprised. We had security that rivaled even the standards required by the banks. Truly crazy high multiple physical key paired with vault and some faraday cage protected offline signing thing — I wasn’t privy to it all just saw bits of it while it was being implemented. Suffice to say it can be done and by going off cloud you get the flexibility to do things like this but... in the end it’s overkill

For every 1 of those crazy high security companies, there’s probably 1000’s that couldn’t secure MongoDB instances.

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#156
post #141

Here in Germany I used to work for a company that swore off Amazon and other US cloud vendors because of things like this: the relationships between them and the government are too tight. They didn’t want German user data being compromised. It could have been FUD to do things on premises or what not but it seemed to make sense at the time and now with this...

This is such a ridiculously primitive view of the world it beggars belief. By taking this view you are significantly reducing your security posture, no improving it. There is an AWS Region in Germany. Your data will stay in Germany unless you specifically decide to move it elsewhere. AWS also provide you with the tools to encrypt everything and if done correctly means that Amazon no matter how "evil" they are cannot…

My bigger worry would be continued data access. So even if the data is in Germany, access to it is still controlled by an US entity, which can be forced by the US government to shut off access. Given that the current administration seems to enact embargos on a whim, this doesn't seem too unlikely.

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#157

Not installing any Alexa’s in my new house. They suck anyway. Literally no practical use cases after 3 years other than being surveiled upon. Oh, and “what’s the weather on the other side of this sheet of glass I’m standing looking through? “ Lol

> Oh, and “what’s the weather on the other side of this sheet of glass I’m standing looking through? “ Lol

Lol that's me.

I also use it to set timers while cooking, and play music (I think the sound of Alexa is quite good). But that's basically it.

A wireless speaker that can set timers / arams, and maybe control music, would allow me to replace Alexa. Is there something like this ?

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#158

How can an ostensibly consumer and business targeted company company allow someone so anti-consumer on the board? Why doesn't anyone have the balls to say "this guy shouldn't be on our board because if we have someone in cahoots with the spooks on our board people will buy less dragon dildos and .223 fuel filters and the sketchy SAAS providers will use less AWS for their crap because their customers will be worried a…

Who's buying dragon dildos on Amazon? Well ... I just searched and it seems they are available there. I did not know that. The real question is why is an ex-NSA agent working at a place that sells dragon dildos? In all seriousness though, if Amazon can predict what consumers want, they will make more sales. An ex-NSA should have at least some experience in analyzing behavioral data and predicting what large numbers o…

In my opinion, it's highly unlikely the ex NSA chief has any kind of worthwhile expertise in "predicting what large numbers of people do". He's a director, not some kind of universal expert or superhero.

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#159

Earlier quoted context omitted.

I'm not devops, but how hard is it to properly set up VPN / ssh ? We have a gitlab server, and connecting requires being on VPN, which requires 2FA, and then ssh, which requires your keys to be properly set up.

Parent comment is talking about self hosting “Google Docs, S3, Dropbox, GitHub, Slack“. Running all those things (and more) instead of focusing on your core business is probably a mistake for most companies.

You could still host it in a country with a less bad track record of industrial espionage.

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#160
post #141

Earlier quoted context omitted.

This is such a ridiculously primitive view of the world it beggars belief. By taking this view you are significantly reducing your security posture, no improving it. There is an AWS Region in Germany. Your data will stay in Germany unless you specifically decide to move it elsewhere. AWS also provide you with the tools to encrypt everything and if done correctly means that Amazon no matter how "evil" they are cannot…

>Your data will stay in Germany unless you specifically decide to move it elsewhere. Prove it

Why don't I prove the earth isn't flat while I'm at it? Oh wait, I can't. I guess you win. Clearly my inability to prove the earth isn't flat means that it is flat.

See how ridiculous you sound? You think that 25,000+ employees that work at AWS have somehow been silenced into some grand conspiracy? The underlying architecture of an AWS Region is fundamentally designed to keep data in the Region you specify. There is no physical way for it to move between Regions without you specifically logging in and telling it do so. Not only that its extremely expensive to move that data around. You pay for this in Region to Region transfer costs. Believe me AWS would not want this happening for free.

That brings me to my other point: AWS don't give a flying fuck about your your boring corporate data either by the way. What they really want is to replace your old expensive insecure data centre hosting shitware like SAP.

If you think AWS are secretly peering into your data to make the Amazon global cabal more powerful then you may as well unplug your datacenter and go back to the Stone Age. It'd be FAR easier for AWS to simply exploit some security vulnerabilities is your decades old, half-baked piecemeal built datacenter and syphon intelligence that way than it would be to try and attack their own cloud services.

Post reply on HN