Live data from Hacker News

Interview with an anonymous AWS cybersecurity engineer

logicmag.io

41–50 of 71 posts

Re: Interview with an anonymous AWS cybersecurity engineer

#41

But when funding dries up for startups and companies have to shutter, then all of their digital operation overseas is cut loose. And the people who lose their jobs go into cybercrime. They think, “There's no other options for me. So sure. Let's do it. Lock and load.” this section is just nonsense. So the crisis happens then devs in "developing countries" become cybercriminals ? total bs ...

Are you telling me you've never gone and downloaded a car after getting laid off?

Re: Interview with an anonymous AWS cybersecurity engineer

#42
post #20

Kind of tangential, but > If you're working in Seattle for Amazon and you're good at your job and you want to leave your job tomorrow, you have far fewer opportunities. Where are you going to go, Microsoft? There's not nearly as much mobility. So I think a big part of the reason we have less organizing [than Google] is that people are more afraid to jeopardize their jobs. If you want to stay in the Northwest, you kee…

There a lot of tech companies in Seattle, many of which are growing their head count. I'd say it's just as good a job market as SF or NY, albeit slightly smaller.

I don't buy the BS from the interview/blog article.

No Amazon engineer I know was worried about leaving/loosing their job. All but one said their engineering culture wasn't fun to work in, and they all left before fully vesting... so i wouldn't say they were held hostage in any way.

Re: Interview with an anonymous AWS cybersecurity engineer

#43
Surprisingly doesn't read like a hit piece. It actually sounds like a real AWS engineer. There's some good about Amazon/AWS, and some bad. That's my experience and the experience of most of my colleagues.

Of course, the anti-Amazon mob will just call this a PR puff piece. But it doesn't read like it to someone who actually works in cybersecurity at AWS.

Re: Interview with an anonymous AWS cybersecurity engineer

#45
post #18
post #15

Earlier quoted context omitted.

It is verging on irresponsible journalism to give this person anonymity without providing any details on their knowledge or credentials and seemingly spending no effort challenging or fact checking any of these answers. That isn't how these pieces are supposed to be written.

There's a massive off vibe for me in things like > So if you have cancer and you might die from your cancer, we won't help you get treatment It just feels.. off. I wouldn't go as far to say the person doesn't work at Amazon at all and instead wants to jab at them but I'm definitely thinking it loudly

The point was regarding fulfillment center workers who don't work enough hours to get company healthcare. That is how it's handled.

If you get cancer or any other major medical catastrophe, Amazon won't do anything to you if you're a part time worker without health insurance. But even if you don't have the health insurance, Amazon will provide support if you catch COVID. Because it's good business to not have one uninsured person to expose an entire shift to a highly communicable disease.

Re: Interview with an anonymous AWS cybersecurity engineer

#46

> The second-largest private employer in the United States after Walmart Neither company is private. They’re both public companies. This is the second sentence in the article. The rest of it sounds made up

I think the private qualifier here is to exclude governments, since the US and state governments employ a _lot_ of people.

Re: Interview with an anonymous AWS cybersecurity engineer

#47
post #40

This reads a lot like a PR piece for Amazon, with most "answers" promoting Amazon nearly like a press release and very little negative points. A few sentences that stand out: > If you have a ton of data in your data center and you want to move it to AWS but you don't want to send it over the internet, we’ll send an eighteen-wheeler to you filled with hard drives, plug it into your data center with a fiber optic cable…

This absolutely has to be a PR piece, or one filtered through a marketing layer of some sort. The only thing that threw me for a loop are the negative points, but this could just be a clever ploy to further the deception. The company we pay to do marketing has all kinds of ridiculous tricks they propose, so I wouldn't be surprised if this is a thing.

Speaking as someone who worked in the PR sector. This reads like an article crafted to influence public opinion by polish the truthful elements while downplaying their flaws.

It's been established that "selective whistleblowing" articles are deemed to be more trustworthy than official marketing statements. Therefore, it would be foolish for corporates to not exploit that to their advantage.

Re: Interview with an anonymous AWS cybersecurity engineer

#48
"These days, the company takes security extremely seriously. I think you'd be hard-pressed to find many nation states that have as sophisticated a security approach as Amazon does."

Sounds like PR fluff. Maybe the crappy nation states have poorer posture, but decent nation states tend to have decent knowledge of security principles, decent isolation of data and tenants within networks, various physically enforced unidirectional links and decent actionable threat intelligence, none of which are necessarily evidenced for Amazon by the interviewee. Additional evidence to back the claim would have been nice. I am not saying nations do not make security mistakes, they make plenty, but I am not convinced it is due to a somehow inferior or less sophisticated approach.

"They might, but ultimately the security standards of their data centers are always going to be lower than those of a cloud provider like AWS. A cloud provider has many tenants and they can have economies of scale that let them have more sophisticated security systems than someone fully managing their systems in-house."

Interestingly, the economies of scale argument, while true, cuts both ways, because there is an economic limit to securing shared infrastructure. The business model of AWS and other CSPs is to multiplex access to shared resources, thereby introducing multi-tenancy issues as well as putting more eggs in the one basket, which is much more lucrative for an adversary to target. I think a mature cybersecurity engineer should be aware of the tradeoff, seems this one is somewhat biased.

I am not sure if it is intentional, but marketing a big truck with guns may be capitalizing on conflating security with the perception of security. Can someone please explain why the truck being giant adds to security? Is it harder for it to roll over on the freeway and cause bits to spill?

Re: Interview with an anonymous AWS cybersecurity engineer

#49
post #39
post #6

What’s an example of a division that AWS subsidizes particularly heavily? Prime Video, for one. Jeff loves Prime Video because it gives him access to the social scene in LA and New York. He’s newly divorced and the richest man in the world. Prime Video is a loss leader for Jeff’s sex life errm... That should be on their SEC risk report

I find it hard to believe that "subsidizing Prime Video" is the only way for Jeff Bezos to gain entry to the LA/NYC social scenes.

Agreed. Also, Prime Video IS a major incentive for a lot of people to sign up for Amazon Prime and thereby helping perpetrate their near monopoly - so I guess it's a win win for Amazon and for Jeff's sex life.

Re: Interview with an anonymous AWS cybersecurity engineer

#50
post #18

Earlier quoted context omitted.

There's a massive off vibe for me in things like > So if you have cancer and you might die from your cancer, we won't help you get treatment It just feels.. off. I wouldn't go as far to say the person doesn't work at Amazon at all and instead wants to jab at them but I'm definitely thinking it loudly

To me it feels like someone was kind of bullshitting with their friends and maybe making themselves seem more knowledgeable and important than they really are. It's totally irresponsible to put it in print.

Very much this. They don’t speak in a way that makes me think they have any internal knowledge of the areas they are speaking about.
Post reply on HN