Live data from Hacker News

Private Ubuntu Cloud

ubuntu.com

21–26 of 26 posts

Re: Private Ubuntu Cloud

#21
post #19

Earlier quoted context omitted.

There is no such thing as an "MP5 uzi".

I guess you're right, but they look like uzis enough for me, and is otherwise a compact submachine gun. What I'm referring to specifically is this, I believe: http://en.wikipedia.org/wiki/Heckler_%26_Koch_MP5

Do the Mp5 Uzi's protect against people that legitimatly have access, or how about a repairman? or during a fire drill - all doors open?

Re: Private Ubuntu Cloud

#22
post #21
post #19

Earlier quoted context omitted.

I guess you're right, but they look like uzis enough for me, and is otherwise a compact submachine gun. What I'm referring to specifically is this, I believe: http://en.wikipedia.org/wiki/Heckler_%26_Koch_MP5

Do the Mp5 Uzi's protect against people that legitimatly have access, or how about a repairman? or during a fire drill - all doors open?

Presumably, everyone on the entire campus is trusted to be there, with increasing layers of security. There are guards posted at all entrances to the campus, where I have to present a badge + window sticker to get on. Once on campus and parked, a swipe card gets me into the building, where I am presented with an X-Ray machine for my belongings and a metal detector that I have to walk through for entrance.

If I am taking any property on or off campus, I have to also present a property pass signed by someone with the authorization to allow that activity.

Admittedly, I could probably sneak a flash drive on if I were so inclined, but that's probably why they do background checks on people before they're given badges and swipe cards and all that.

Re: Private Ubuntu Cloud

#23
post #20
post #15

Earlier quoted context omitted.

Federal government is almost certainly what he's talking about. We have heavily guarded rooms with impressive physical security, and authorized personnel only, in which the two networks can be 'viewed' at the same time. For what it's worth, the majority of end users don't have two machines, they either visit a secured location when they need to, or have devices / software that only allow them to connect to one networ…

ok fine I have seen these type of examples but where is the weakest link - e.g. does this super secret segregated network backup to unencrypted tape which is then lost or stolen ( http://bit.ly/cQZiRd ) a hard drive stolen ( http://bit.ly/aLH2xI ), a legitimate user walks out with info ( http://bit.ly/b8Iecp ), a laptop stolen ( http://bit.ly/cp0h5Q ) The point I'm trying to make is you have to look at security holis…

I think we're deviating away from the real topic at hand, but regardless, I couldn't say specifically what the weakest link is... while I know that the tapes themselves have their own procedures, I don't know what they are.

The 'legitimate users' issue is largely mitigated from malice by severely limiting who those users are with background checks, security clearances, layered access levels, and a culture in which everybody reinforces the security procedures and watches for others who might be violating them, intentionally or unintentionally. This isn't 100% of course, nothing is, but it's largely effective I would guess.

Stolen laptops of course happen on occasion, but it's a dramatically different problem than unintentional access to a data center, or all the data therein. Further, most of the laptops I've seen have data-at-rest encryption, remote locating devices (GPS) and fairly stringent security protections on the device. In order to connect to any sensitive networks, they'd also have to use VPN and 2 factor encryption.

Largely, these things have already been thought of... but more importantly, if you're statement holds weight, and they should have stringent controls everywhere to be effective, then why would they arbitrarily allow their data to be potentially compromised in the event that Amazon has less stringent requirements -- and guess what, they do.

Re: Private Ubuntu Cloud

#25
post #23
post #20

Earlier quoted context omitted.

ok fine I have seen these type of examples but where is the weakest link - e.g. does this super secret segregated network backup to unencrypted tape which is then lost or stolen ( http://bit.ly/cQZiRd ) a hard drive stolen ( http://bit.ly/aLH2xI ), a legitimate user walks out with info ( http://bit.ly/b8Iecp ), a laptop stolen ( http://bit.ly/cp0h5Q ) The point I'm trying to make is you have to look at security holis…

I think we're deviating away from the real topic at hand, but regardless, I couldn't say specifically what the weakest link is... while I know that the tapes themselves have their own procedures, I don't know what they are. The 'legitimate users' issue is largely mitigated from malice by severely limiting who those users are with background checks, security clearances, layered access levels, and a culture in which ev…

You've done a good job answering the question asked of me -- thank you.

To add a little more, in places where security really matters, like DoD manufacturing areas, there is literally physical security segregating everything from the people to the network to the hardware to the data from the unclassified parts. Knowing you could go to jail for a very long time if you do something stupid or illegal is a strong motivator. For those not so motivated, most places not only segregate the network but also the data: tapes or backup data are kept onsite in a secure area, computers used for interacting with the data never leave the secure area and have been modified not to have USB headers or removable hard drives, cables and gear are physically protected from tampering, etc.

None of this is to say that all risk is eliminated, but since most systems are compromised by casual hackers using simple tools, adding the security you can is usually a sensible thing to do.

Re: Private Ubuntu Cloud

#26
post #25
post #23

Earlier quoted context omitted.

I think we're deviating away from the real topic at hand, but regardless, I couldn't say specifically what the weakest link is... while I know that the tapes themselves have their own procedures, I don't know what they are. The 'legitimate users' issue is largely mitigated from malice by severely limiting who those users are with background checks, security clearances, layered access levels, and a culture in which ev…

You've done a good job answering the question asked of me -- thank you. To add a little more, in places where security really matters, like DoD manufacturing areas, there is literally physical security segregating everything from the people to the network to the hardware to the data from the unclassified parts. Knowing you could go to jail for a very long time if you do something stupid or illegal is a strong motivat…

Look two good replies and I think we are all in agreement that the military will probably not be using public cloud services any-time soon (at least not until budget cuts > security concerns) and if the OP is targeting purely that of market with that risk appetite then good luck to them.

My main point was that for most corporations and individuals the risk of using a public cloud with effective security controls and the right kind of data stored and processed there could be within their risk appetitive and therefore private clouds have no long term high profit making potential

Post reply on HN