Earlier quoted context omitted.
> So 3 employees involved with security and not 1 employee. Also, they were pushed out AFTER alerting about security issues. How much credibility do you put in such testimonies though? Especially if everyone is a "anonymous source", you can basically invent just about anything and publish it and pretend for it to be a genuine article without any fact under the hood.
You get sued, because such claims are business damaging.
Amazon insiders sound alarm over security
31–40 of 63 posts
Re: Amazon insiders sound alarm over security
#32Every time I read articles like these, I get dissapointed about the state of the internet. The only thing you know that is likely to be true is that someone got fired from Amazon, and thats it. You don't know if they are telling the truth. You don't know if they were in the right. You don't know if Amazon was fixing the problem, and they decided to be an asshole and go over their bosses because they felt that not eno…
FWIW I’ve never worked for Amazon, but I have quite a few friends and former coworkers at AWS. We’ve had discussions about security and privacy, and the general sense I got from them is that Amazon has more of a focus on security and privacy than any tech company they’ve previously worked for.
Re: Amazon insiders sound alarm over security
#33Somehow I am not surprised given all the talk about toxic culture at Amazon from current and past employees.
I personally know a couple ex-Amazon people who thought it was a good place to work and thrived there. Of course, that's not worthy of writing a newspaper article about :-/ I'm not saying it is or it isn't. But ask yourself, which viewpoint sells more newspapers?
Re: Amazon insiders sound alarm over security
#34Earlier quoted context omitted.
> So 3 employees involved with security and not 1 employee. Also, they were pushed out AFTER alerting about security issues. How much credibility do you put in such testimonies though? Especially if everyone is a "anonymous source", you can basically invent just about anything and publish it and pretend for it to be a genuine article without any fact under the hood.
Journalists do check the credentials of the people they include in articles like this. They don't just take randos at their word. These people are anonymous to you but not to the journalist. If you simply don't believe the writer that's a totally different issue - but people at major outlets like Politico don't just invent sources and stories out of whole cloth like you suggest.
Re: Amazon insiders sound alarm over security
#35Earlier quoted context omitted.
And how does this solve the problem of information security?
Moving away from a few megacorps would mean consumers have choice in selecting an alternative provider who takes privacy and security more seriously. Today that choice doesn’t exist because Google, Amazon, Facebook, and other big tech companies don’t face competition either due to a traditional monopoly/oligopoly traits, extreme capital advantages, or network effects.
Re: Amazon insiders sound alarm over security
#36Yikes. Not exactly confidence-inspiring.
Re: Amazon insiders sound alarm over security
#37Earlier quoted context omitted.
The only way to prove it, would be a massive data leak.
The fact there have been no data leaks should tell you more then some anonymous sources
Re: Amazon insiders sound alarm over security
#38Earlier quoted context omitted.
You get sued, because such claims are business damaging.
Good, because then you can verify your claims in court. Which Amazon will not be able to counter. So they will fear the light. Like their friends, secret services doing their illegal things, but they are protected by "National Security" claims, Amazon not.
Re: Amazon insiders sound alarm over security
#39Its good they are sounding the alarm, for example, Crypto AG had their cryptographer employees continually find security flaws only to have upper management tell them to work on something else, only to find out after 50 years that it was a CIA operation selling backdoored products to nation states. With nothing being outside the realm of possibility, removing the need for trust should be priority number one.
I would be very interested if you could share accounts of this happening.
From the declassified documents I have studied the Crypto AG "backdoor" consisted of misleading customers that less complex models (with smaller keys) would be suitable for their communications, working with the NSA to word end user documentation in a way that makes it unclear how important specific settings are, and providing technical designs to the NSA for review.
At no point do I believe there was a security flaw that an employee would have found that would have compromised the operation, since it was simply a series of steps that weakened the strength of the encryption from "mathematically impossible" to "requires a purpose built supercomputer." This route provided plausible deniability to everyone involved (remember that other cryptographers also evaluated Crypto AG products and would work to secretly exploit any flaws they found "for the bad guys").
Interestingly before the CIA/BND deal, the French attempted to secretly buy the company and do the exact same thing.
Re: Amazon insiders sound alarm over security
#40Earlier quoted context omitted.
The only thing you know that is likely to be true is that someone got fired from Amazon. From the article: > The warnings about privacy and compliance failures at Amazon come from three former high-level information security employees — one EU-based and two from the U.S. So 3 employees involved with security and not 1 employee. Also, they were pushed out AFTER alerting about security issues.
> So 3 employees involved with security and not 1 employee. Also, they were pushed out AFTER alerting about security issues. How much credibility do you put in such testimonies though? Especially if everyone is a "anonymous source", you can basically invent just about anything and publish it and pretend for it to be a genuine article without any fact under the hood.