Live data from Hacker News

Private Ubuntu Cloud

ubuntu.com

11–20 of 26 posts

Re: Private Ubuntu Cloud

#11
post #10
post #4

I'm sorry but the whole concept of a private cloud makes no sense to me - why would you have a private electricity generator for your home? The security issues are a lot of fear, uncertainty and doubt (FUD), I have written about it here: http://rakkhi.blogspot.com/2010/07/cloud-computing-security-...

It's only FUD if you don't consider physical security at all important. When you're working with VERY sensitive data (the kind that mishandling could literally get you arrested for), you seek to secure it in every way possible. Perhaps ironically, a white-listed firewall rule for a cluster of EC2 instances is probably more secure than most government networks, but putting it anywhere that compromises physical securit…

Its not that I don't consider physical security as important - I just do not think that the physical security provided by your private data centre is any better than what Amazon provides. The economies of scale and the motivation to avoid a massive security incident that affects all their customers is just greater than what you have with internal IT.

But of course do a risk assessment, maybe military data should not be on any sort of cloud. But I know internal government and military security is actually pretty poor - funnily enough generals care more making sure their comms work to their soldiers than whether it is encrypted - sound kind of like a business eh?

Either way I predict that within 5 years, private clouds will be a thing of the past

Re: Private Ubuntu Cloud

#12
post #11
post #10

Earlier quoted context omitted.

It's only FUD if you don't consider physical security at all important. When you're working with VERY sensitive data (the kind that mishandling could literally get you arrested for), you seek to secure it in every way possible. Perhaps ironically, a white-listed firewall rule for a cluster of EC2 instances is probably more secure than most government networks, but putting it anywhere that compromises physical securit…

Its not that I don't consider physical security as important - I just do not think that the physical security provided by your private data centre is any better than what Amazon provides. The economies of scale and the motivation to avoid a massive security incident that affects all their customers is just greater than what you have with internal IT. But of course do a risk assessment, maybe military data should not…

Except that you can physically segregate it from the public network... or even the majority of your internal LAN/WAN.

Private clouds will only continue to gain momentum in the enterprise, especially as they become easier to deploy & manage.

Re: Private Ubuntu Cloud

#13
post #12
post #11

Earlier quoted context omitted.

Its not that I don't consider physical security as important - I just do not think that the physical security provided by your private data centre is any better than what Amazon provides. The economies of scale and the motivation to avoid a massive security incident that affects all their customers is just greater than what you have with internal IT. But of course do a risk assessment, maybe military data should not…

Except that you can physically segregate it from the public network... or even the majority of your internal LAN/WAN. Private clouds will only continue to gain momentum in the enterprise, especially as they become easier to deploy & manage.

The difference between can and do

I have never worked in a company that physically segregated their internal network to one connected to the internet - and I have worked in Fortune 50 banks, credit card processors and online businesses. Like I said military maybe different but I know colleagues that work for the government and you should hear about how their security actually is vs. the perception (much like banks)

It is hard enough to get companies to segment their network into high value services vs the office network. The practical difficulty and cost of giving end users two machines connected to two different networks is just not worth the benefit gained.

Especially considering you can achieve a level of risk that is acceptable to the board and executive management with logical controls private clouds are just a waste of money.

Re: Private Ubuntu Cloud

#14
post #11
post #10

Earlier quoted context omitted.

It's only FUD if you don't consider physical security at all important. When you're working with VERY sensitive data (the kind that mishandling could literally get you arrested for), you seek to secure it in every way possible. Perhaps ironically, a white-listed firewall rule for a cluster of EC2 instances is probably more secure than most government networks, but putting it anywhere that compromises physical securit…

Its not that I don't consider physical security as important - I just do not think that the physical security provided by your private data centre is any better than what Amazon provides. The economies of scale and the motivation to avoid a massive security incident that affects all their customers is just greater than what you have with internal IT. But of course do a risk assessment, maybe military data should not…

The physical security in MY data center has armed guards carrying MP5 uzis, and has absolutely zero tenancy except for us.

I personally feel that the data there is quite safe, relatively speaking.

Re: Private Ubuntu Cloud

#15
post #13
post #12

Earlier quoted context omitted.

Except that you can physically segregate it from the public network... or even the majority of your internal LAN/WAN. Private clouds will only continue to gain momentum in the enterprise, especially as they become easier to deploy & manage.

The difference between can and do I have never worked in a company that physically segregated their internal network to one connected to the internet - and I have worked in Fortune 50 banks, credit card processors and online businesses. Like I said military maybe different but I know colleagues that work for the government and you should hear about how their security actually is vs. the perception (much like banks) I…

Federal government is almost certainly what he's talking about.

We have heavily guarded rooms with impressive physical security, and authorized personnel only, in which the two networks can be 'viewed' at the same time.

For what it's worth, the majority of end users don't have two machines, they either visit a secured location when they need to, or have devices / software that only allow them to connect to one network OR the other at a time.

Generally speaking though, the network that has access to tactical data, or knows the most recent whereabouts of Saddam Hussein is typically ignorant of Facebook, or the internet at large.

Re: Private Ubuntu Cloud

#16
This only seems like a good idea for larger organizations. The idea would be to share a pool of server resources among many working groups with assumptions:

1. server utilization on average would be good

2. seldom have the situation where everyone wants to do large runs at once

At CompassLabs we use Elastic MapReduce: great because we can use a large number of servers for a few hours, and the price is right. On the other hand, large companies like Yahoo run their own large Hadoop clusters (just as an example)

So, this seems like a good idea only for large organizations.

Re: Private Ubuntu Cloud

#17
post #14
post #11

Earlier quoted context omitted.

Its not that I don't consider physical security as important - I just do not think that the physical security provided by your private data centre is any better than what Amazon provides. The economies of scale and the motivation to avoid a massive security incident that affects all their customers is just greater than what you have with internal IT. But of course do a risk assessment, maybe military data should not…

The physical security in MY data center has armed guards carrying MP5 uzis, and has absolutely zero tenancy except for us. I personally feel that the data there is quite safe, relatively speaking.

There is no such thing as an "MP5 uzi".

Re: Private Ubuntu Cloud

#19
post #14

Earlier quoted context omitted.

The physical security in MY data center has armed guards carrying MP5 uzis, and has absolutely zero tenancy except for us. I personally feel that the data there is quite safe, relatively speaking.

There is no such thing as an "MP5 uzi".

I guess you're right, but they look like uzis enough for me, and is otherwise a compact submachine gun.

What I'm referring to specifically is this, I believe: http://en.wikipedia.org/wiki/Heckler_%26_Koch_MP5

Re: Private Ubuntu Cloud

#20
post #15
post #13

Earlier quoted context omitted.

The difference between can and do I have never worked in a company that physically segregated their internal network to one connected to the internet - and I have worked in Fortune 50 banks, credit card processors and online businesses. Like I said military maybe different but I know colleagues that work for the government and you should hear about how their security actually is vs. the perception (much like banks) I…

Federal government is almost certainly what he's talking about. We have heavily guarded rooms with impressive physical security, and authorized personnel only, in which the two networks can be 'viewed' at the same time. For what it's worth, the majority of end users don't have two machines, they either visit a secured location when they need to, or have devices / software that only allow them to connect to one networ…

ok fine I have seen these type of examples but where is the weakest link - e.g. does this super secret segregated network backup to unencrypted tape which is then lost or stolen (http://bit.ly/cQZiRd) a hard drive stolen (http://bit.ly/aLH2xI), a legitimate user walks out with info (http://bit.ly/b8Iecp), a laptop stolen (http://bit.ly/cp0h5Q)

The point I'm trying to make is you have to look at security holisticly. Having a super strong segregated network has no point if you are not going to have a similar level of control everywhere else which I can guarantee you the Federal government especially in the US does not have.

So why not take advantage of the cloud, enjoy the cost decrease, increase in resilience and scalability and still have an acceptable level of risk with application of reasonable logical controls?

Post reply on HN