Live data from Hacker News

Former NSA chief Keith Alexander has joined Amazon’s board of directors

theverge.com

341–350 of 465 posts

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#341

Earlier quoted context omitted.

I don't know... I don't think there's a strong business case or CSO case for ditching Amazon for ties to yhe US gov't. What are the realistic odds that someone internally at Amazon is going to break into your instances to look at your data if you're just a regular business? If you're in a German cloud, those risks are probably higher since your business has local competition, and if you're self-hosting, then your ove…

> What are the realistic odds that someone internally at Amazon is going to break into your instances to look at your data if you're just a regular business? I mean, there's this: https://www.wsj.com/articles/amazon-scooped-up-data-from-its... > The online retailing giant has long asserted, including to Congress, that when it makes and sells its own products, it doesn’t use information it collects from the site’s ind…

That is an apples to oranges comparison.

It is wildly different to scoop up data from your own Amazon.com platform vs BREAKING IN to a private AWS instance. They aren't even the same divisions in Amazon Inc, so it would be extremely obvious to everyone, very inappropriate, and most likely get leaked that it was happening.

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#342

Earlier quoted context omitted.

Postwoman might be enough for you if looking for a replacement and it's FOSS

Depending on what you're doing, just use curl

Just like you could just use nano in place of IntelliJ.

But the idea that Postman is actually git in that analogy is hogwash and a way to wrest data out of people.

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#343

Earlier quoted context omitted.

I don't know... I don't think there's a strong business case or CSO case for ditching Amazon for ties to yhe US gov't. What are the realistic odds that someone internally at Amazon is going to break into your instances to look at your data if you're just a regular business? If you're in a German cloud, those risks are probably higher since your business has local competition, and if you're self-hosting, then your ove…

Oh, come on. This kind of naïveté is contagious. I'm pretty sure you can think of stronger business cases against Amazon/US-Milspec involvement in a non-American business. Amazon, in the hands of Americas spooks, can do a lot of damage to the world of non-Americans; i.e. anyone the spooks decide to hate/target for usurpation. You think Germany is inured from such attention?

I think your being overly paranoid. The effort required to covertly break into an AWS instance and not have anyone in the sysadmin teams know is simply not worth it for 99.9% of businesses.

I run a simply mid-level business. Amazon doesn't give a crap about my data - that, above all, is what keeps it safe. I'm just not important enough to bother.

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#344

Earlier quoted context omitted.

But it's hard to avoid the cheap offerings of US cloud. I'm from Sweden myself and I'm only speaking as a layperson who is observing the IT industry. It feels like the rampant capitalism in the United States, and lack of regulations, fuels the VC economy. Making startups like Google, Amazon and others possible. I can't imagine a company running on hundreds of millions in dollars of VC money with no real profit coming…

Eh. I don't get it. There have been so many postings and comments here on HN and elsewhere about how the cloud is NOT cheap, how they saw they burnt money there, and saved large amounts by doing it for themselves. Not to mention vendor lock in.

A lot of folks mis-configure / mis-manage their instances so as to use way more resources than they really need.

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#345

Earlier quoted context omitted.

I think you’re really overestimating the ability of most small tech companies to self-host reliably and securely.

I'm not devops, but how hard is it to properly set up VPN / ssh ? We have a gitlab server, and connecting requires being on VPN, which requires 2FA, and then ssh, which requires your keys to be properly set up.

You have to do some planning, but it isn't too hard. The most issues arise from compromises between security and convenience. Cloud services can offer both in the best case, but aside from O365, which is really sluggish, we are actually in the process of migrating back to on premise solutions.

Nobody attacks code repositories of non-software companies anyway, people are after CRM and ERP data. There is the occasional issue with malware from mails and special users, but a backup solution with 15min snapshots solves that issue. Although the latter can cost a bit and might be too expensive for smaller companies.

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#346

Here in Germany I used to work for a company that swore off Amazon and other US cloud vendors because of things like this: the relationships between them and the government are too tight. They didn’t want German user data being compromised. It could have been FUD to do things on premises or what not but it seemed to make sense at the time and now with this...

Are you sure you didnt spell "China cloud" and "Huawei" wrong? /s Just because we (Germans, Europeans) are culturally closer to Americans and share certain values does not mean that we should have a double standard on our external affairs. We are kicking out Huawei. When will we kick out Amazon, Google, Apple and Cisco?

You answered your own question. We can't control Huawei so goodbye. The others we can so they get to stay.

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#347

Earlier quoted context omitted.

This bullshit game of "which is worse" between the US and China, with both countries constantly moving the goalposts, is just tiring. Yes, China is currently worse. But with children locked up in cages and a massive prison-slavery industry, not to mention crazy NSA spying and so on, you're kidding yourself if you say the US is that far behind. You can say, as a US citizen, that all this stuff doesn't affect you much.…

The difference is that here we have the freedom to criticize and organize against it. One of the presidential candidates wants to tear down all the stuff you pointed out. I can say that the surveillance doesn't affect me because it's almost unheard of for Americans to get arrested with evidence that the NSA collected. The NSA is not a law enforcement agency. In China arresting people based on data from surveillance i…

> One of the presidential candidates wants to tear down all the stuff you pointed out.

"All the stuff" that was either started or expanded while he was VP. Yeah, sure he wants to tear it down.

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#348
post #141

Earlier quoted context omitted.

This is such a ridiculously primitive view of the world it beggars belief. By taking this view you are significantly reducing your security posture, no improving it. There is an AWS Region in Germany. Your data will stay in Germany unless you specifically decide to move it elsewhere. AWS also provide you with the tools to encrypt everything and if done correctly means that Amazon no matter how "evil" they are cannot…

> there is such a huge separation in access and rigour around governance that there is no way anyone within Amazon can simply login and see your data even if unencrypted. I personally choose not to believe a company which puts on its board of directors a well-known perjurer [1]. [1] https://www.theguardian.com/commentisfree/2013/sep/25/nsa-re...

Don't forget the mass surveillance of his old job. Even if he didn't lie, you might want to think of hiring him for your cloud services.

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#349
post #275

Earlier quoted context omitted.

My company self hosts everything. They’re so bad at it. Something is always down and we waste so much time with our shorty tooling. We even had this amazing idea that we could implement our own version of GCP from scratch. The result is dismal, we dread using it because it’s very unreliable, and it costs double or triple what GCP costs. We’re not a small company, we have about 1k employees and our business is softwar…

A tradeoff might be to keep encrypted data on GCP with keys managed on-premise with transparent encryption decryption by way of a local proxy.

Most businesses need a lot more than dumb storage from their IT systems though...

As soon as you start using the full suite of cloud tools, it's impossible to not give the provider the encryption key...

Re: Former NSA chief Keith Alexander has joined Amazon’s board of directors

#350

Here in Germany I used to work for a company that swore off Amazon and other US cloud vendors because of things like this: the relationships between them and the government are too tight. They didn’t want German user data being compromised. It could have been FUD to do things on premises or what not but it seemed to make sense at the time and now with this...

Are you sure you didnt spell "China cloud" and "Huawei" wrong? /s Just because we (Germans, Europeans) are culturally closer to Americans and share certain values does not mean that we should have a double standard on our external affairs. We are kicking out Huawei. When will we kick out Amazon, Google, Apple and Cisco?

Are Huawei and Amazon/Google/Apple/Cisco equivalent?

Is the "spying" by the US on Germany as damaging to Germany's future as spying by the Chinese?

If you answer these questions honestly, you'll understand why you're making a false equivalence.

Post reply on HN