Announcing the New AWS Secret Region
aws.amazon.com
aws.amazon.com
I've argued this before around here - I believe it's a platform provider's responsibility for the most part to secure data, and less so the responsibility of the developer or user. Amazon should go much further and make it hard to open-up the data to the public, at least for certain categories of buckets.
So for instance some buckets should always be public by default, and some should always be encrypted and private by default. That should make intelligence agencies' choice easier, because I would imagine even if it's "harder" to process the data from an encrypted bucket, they would still prefer that option to the always public bucket.
And maybe both categories could still be configured to either be private or public, respectively, but the account owners should have to really go out of their way to make those changes. So most shouldn't bother, and just use the defaults for each category of buckets.
I would say that is going too far, or maybe I'd say it differently. If a certain problem becomes very frequent relative to it's severity, the problem is a design bug and not just user error. The provider isn't responsible for every mistake, but they are responsible for designing with mistakes in mind.
I think we are way far away from users fully understanding the risks, and we're still mostly dealing with people not realizing they're vulnerable. So I put this primarily on the provider.
I wonder what other improvements we'll see when CIA's surveillance or drone strike data is also exposed to the public by a similar fuckup? Fully homomorphic encryption?
Does this mean they already had an AWS "Top Secret" Region?
Microsoft announced their version a few weeks ago[1]. I wonder if Google will follow shortly?
[1] https://azure.microsoft.com/en-us/blog/announcing-new-azure-...
[1] but in such a poorly tested, underbaked fashion you probably shouldn't bother for a few years
> authorized for use with up to High Impact level data
That's not "Secret" or "Top secret"
AWS govcloud has existed for HI for ages; this announcement is specifically for "Secret" classified data.
FedRAMP has multiple levels. Don't conflate the FedRAMP authorizations solely with marketing terms.
to non-Intelligence Community users. You'll still need US Government Secret Clearance though.
Or customers can get a Direct Connect from their existing facilities into the region. I presume the USG has plenty of fiber straight into these new datacenters and I'm not sure why Amazon wouldn't allow Direct Connect.
As someone else mentioned, perhaps this will get contractors to stop using public S3 buckets to share data.
It might also mean that the cloud is connected to networks that are not, themselves, Internet-routed. For example, users of the Secret region might have leased lines connecting airgapped computers in their own facilities directly to the DC for ingress/egress.
It might also mean that the network is connected to a “different Internet”, like MILNET.
The other (unidirectional) method is a fibre pair connection that does not physically connect the TX with the RX in one direction, and there is some bumblefuckery that pushes the data through.
Of course classified data is only transferred from networks with lower classification to networks with higher classification, never the other way.
That is precisely how I would describe the Tenix and/or FOX-IT data pump implementations. It's amazing what people can manage to get away with even at EAL-7+.
(Estimated at approx 10ppm by 20KiB per code.)
For the security conscious on a budget, printing QR codes to scan to a networked machine can be a way to get information off an otherwise air-gapped machine, with easy introspection and auditing. (This came up in the context of offline signing of Bitcoin transactions with a "warm" wallet -- digital, but airgapped from the "hot" wallets.)
PDF: https://www.raytheon.com/capabilities/rtnwcm/groups/gallery/...
From PR:
Raytheon Trusted Computer Solutions (RTCS), a wholly owned subsidiary of Raytheon Company (NYSE: RTN), today announced that its High Speed Guard (HSG) big data transfer solution has received Cross Domain System Authorization and Authority to Operate for Secret and Below Interoperability (SABI).
This allows government customers to connect to networks classified at secret and below, and enables them to start the SABI site test and evaluation toward full system accreditation.
Raytheon's HSG solution is a commercial-off-the-shelf product that enables the rapid transfer of all types of data across multiple networks at different classification levels. With the industry's fastest bi-directional transfer rates of any guard technology and proven sustained transfer rates of more than nine gigabits per second, HSG is ideally suited for large-scale deployments that require rapid, automated data transfer.
Can't they get the NSA to rent them some of their spare capacity from the CNCI? Or is this because they trust Amazon to have actually solved the hard problems?
Basically, AWS is all public cloud, none of this private cloud nonsense... until you come along with a $600MM check and then you can have a private region all to yourself!
I don't see why they would throw at their current billing model for something else.
The government doesn't work like those spy movies where everybody knows everything the instant it happens. It's more like a big bloated corporation with thousands of subcontractors and generally lousy communication all around.
Additionally, if I was doing secret things I'd really think it was not a great idea to put that into a data centre marked "Definitely where I keep all of my secrets".