I'm not sure that Amazon would be able to pierce the veil of the hypervisor like that, but his instincts were in the correct direction.
I'm not sure that Amazon would be able to pierce the veil of the hypervisor like that, but his instincts were in the correct direction.
If they say they won't read your data, better trust them. If you don't, stay away from their datacenters.
EDIT: fix typo.
This is 100% true. To do any useful computation on your data (read, what you're using all AWS for) they have to have 100% visibility into your data.
> If they say they won't read your data, better trust them. If you don't, stay away from their datacenters.
That's it, right there. All of this is based on Trust in Amazon, not some technology that provides any assurances, much less proof, they're not looking at your data.
They can pull the curtain off anything you're running in their cloud, at any time they feel like it. It has to work this way for AWS to be of any use, and by using AWS you're implicitly trusting Amazon with your data.
Similarly, if you're presenting externally, it's a good idea to close open applications that are not relevant to prevent info leaks from Alt-Tabbing.
Actually having a competitor pay someone to come into your office to pick locks etc. is rare, comes with criminal liability and is easily detectable on security cameras.
Then again, compared to the average bear, maybe I'm unusually circumspect when it comes to all of those things.
If for example I'm fully on amazon AWS for everything, DNS/DB/Web then no matter how encrypted your data is Amazon still has a very good idea of the effectiveness of your campaign. You can't hide the number of DNS queries. You can't hide the number of TCP SYNs. Hell, there is just a huge amount of things that encryption does not cover up, especially involving time for particular transactions to occur.
Amazon, if they wanted, could read stats from Netflix’s database about which movies drive the most engagement and use that to determine what to license for Prime video.
It’s the difference between root on the server and capturing encrypted packets on a network.
How else do you think "closed-loop" measurement of marketing effectiveness, and retargeting based on purchase behavior are done? How else do you think suppliers can pull a D&B report on your company showing your bank account balances?
A valuable if painful lesson to learn. I still do all my personal banking with a credit union and consider my relationship with banks to be adversarial. They only own my debt, never my cash.
Is that an exaggeration? It amounts to $100 or $50 a month in "low balance fee"!
All the banks I've looked at had a fee under $10.
How many PayPal horror stories have there been?
For one, banks are far more regulated than Amazon is. If governments funded departments with 10s or 100s of thousands of employees monitoring and regulating cloud computing services, then it might be similar.
But the most significant difference is that if the bank seizes my money, I'll know about it pretty quickly and can respond. If Amazon sniffs through my commercial data, I'm unlikely to ever know. Most people are far more tempted to do wrong if they know if the chances of getting caught are miniscule.
It's the difference between breaking into a Walmart with a ski mask and assault rifle and stealing a bunch of blu rays vs recording the HDMI out from whatever device you stream Netflix from. They're not the same thing at all, either in terms of harm done, applicable criminal law, or ability to build a compelling civil lawsuit.
> If amazon copied all your proprietary data, you would almost certainly never notice, no criminal law would apply, and you'd have a hell of a time proving it in a civil suit.
If Amazon were doing this and profiting from it, that would essentially be a criminal conspiracy that reaches to the leadership of the company. Is it possible? Sure. Is it likely? I tend to think conspiracy theories are rarely true. Would it be caught? I believe it would likely be caught.
Companies get things done by having meetings, informing their hierarchy, and following executive decisions. In what meeting do you imagine this being discussed? Who floats this idea, and who signs off on it? I just don't see it happening. And if it does, I expect whistleblowers to put a stop to it.
Actually, they are quite uncommon, which is why they make headlines when discovered.
I'm not taking a side here, just pointing out a fallacy.
Bezos is making the most money of everyone living. Many of the scandals happen when the founder is retired or dead.
Boeing:
See 737 MAX, other 737 boondoggle like the vertical stabilizer reversal back in 94'ish.
Monsanto, hell, what chemical hasn't hid information they damn well shouldn't:
Dicamba, roundup.. Take your pick. The stellar behavior of this corporate citizen taints cements the stereotype of an entire industry.
https://thecounter.org/dicamba-trial-monsanto-basf-pesticide...
https://www.phillyvoice.com/new-york-times-dupont-hid-decade...
Special mention goes to a certain German pharma company who brought you Thalidomide:
https://en.m.wikipedia.org/wiki/Gr%C3%BCnenthal_GmbH
The lovely folks at Insys:
https://www.nytimes.com/2019/05/02/health/insys-trial-verdic...
Believe there was a fraudulent implant thing a bit ago... Where'd I put that?
https://www.desertsun.com/story/news/health/2014/07/09/south...
Someone beat me to Dieselgate.
Arthur Anderson LLP.
PG&E deliberately skimped on maintenance, leading to fires in California, and if I recall natural gas lines overpressuring in Massachusets?
https://en.wikipedia.org/wiki/Massachusetts_gas_explosions
Excuse me, the natural gas one was Columbia Gas.
Big Tobacco...
Nestle I think getting caught using child labor in their supply chain at one point.
https://www.theguardian.com/global-development-professionals...
Oh what else can I think of off the top of my head? Uhhh...
That's all I can think of for right now. I mean we can hit the history books or case law to get a solid count I suppose, but to be frank, once a company hits a certain revenue point, it is pretty much guaranteed they've had to do something to get dirty/avoid getting outed as dirty.
So it really isn't that unusual. Throw in stuff that happened back before the rise of the Unions of the last century, and since their decline, and you also end up with so.e decent stories of workforce abuse. Though admittedly there's slant depending on who is telling it.
Like the Pinkertons as a matter of fact.
https://en.wikipedia.org/wiki/Pinkerton_%28detective_agency%...
Or the original incarnation of Equifax, who were tasked with vetting prospective executive promotees.
Just because it'sorganized doesn't mean it's doing anyone any favors.
I stand by my statement -- it is rare.
The very least we can say is that company malpractice is more common than it appears, unless 100% of it is reported on.
I know of a case of fraud in oil well lease payouts, someone was stealing a small from a large number of leases and had been doing so for years.
A company auditor caught it. Did they go to the police? No. They paid the guy to leave the company and never talk about it again. The guy might have stolen hundreds of thousands in the process, but the company knew they'd lose millions, just from clients demanding audits going decades back. It was easier and cheaper to cover up and never mention again.
As has been mentioned as well is that governmental/regulatory apparata are typically starved of funding, so must limit their investigation/scrutiny to likely the most obvious cases.
Furthermore, if you've just entered into white collar circles these last few years, you may have been surprised at a tendency to not write things down. This isn't just people not realizing it is a good idea to do so, but a conscious decision in many cases due to eDiscovery, and the effects it has on provability in a court of law.
Pay attention on HN, and you'll get little snippets of other cases of "tribal skeletons" every now and again.
Anyway, by all means, I'm not necessarily arguing against your point; merely stating that given the sample size, and keeping in mind that regulators/the media can only dig up so much muck given limited manpower; it is not prudent to assume there isn't wrongdoing where no one has looked yet. I used to hold the same view you espouse; then I started A)cataloging things and B) noticed how often settlements seem to be applied with no admission of wrong doing.
Absence of evidence does not imply evidence of the non-existence thereof. You just haven't found it yet.
Can't believe I forgot about Wells Fargo, btw. That whole mess.
https://en.wikipedia.org/wiki/Wells_Fargo_account_fraud_scan...
ISP's have been known to falsify their Form 477 data fabricating coverage stats, and overcharging customers:
https://www.cbsnews.com/news/complaints-att-directv-bundled-...
https://www.ripoffreport.com/reports/verizon-wireless/nation...
There's plenty more where that came from with every ISP to be honest.
FTC keeps stats on all enforcement actions apparently. Might be a decent place to start looking to get some solid numbers.
https://www.ftc.gov/enforcement/cases-proceedings/
Mind that that's only the ones. I assume CFPB and other commissions have similar, but do keep in mind they can't be everywhere or investigate everyone. So without stats on how many actions are dropped by prosecutorial/investigator's discretion, it is actually difficult to make really solid claims as to the actual frequency of malfeasance. Further, from my social circle's anecdata, it seems to be a safe bet that just about every organization at least has something in the the way of "muck they've cleaned up after" without getting authorities involved.
Anyway... I've rambled enough.
[0] https://en.wikipedia.org/wiki/Volkswagen_emissions_scandal
main thing here is that in big corps you can divide big (evil) task into smaller steps which could be defined as non-evil in isolation, and nobody in actual implementation people crowd would understand big picture.
For a thought exercise, let's play this out.
Amazon copies data running through VMs (or grabs it from storage).
Let's assume it isn't on hardware certified for capital-letter processing [1], most of which require regular third party audits.
So they have your illegally-obtained data [2], which presumably they want to use to make money.
Except they can't leave any record of its source, in any documented form. This includes server logs, data transfers, emails about data, meeting minutes about data.
So they create some isolated network, run by a third party contractor, that transfers encrypted data from the taps to a store, then decrypts. All of which brings us to the most difficult part.
Who does... what with it?
The source data itself is radioactive. Who knows when "pricing strategy for company X" or obvious equivalent might pop up in the stream?
So you... what? Exclusively touch it via algorithm that outputs only aggregate information? How do you possibly code and maintain that pipeline, sight unseen?
All while risking an incredibly profitable business.
Or, you know, you just operate as an honest IaaS provider and make $10B in revenue / quarter with a 25% growth rate...
The unit could be the "open sales modeling unit" that just supplies one data feed among thousands.
They can certainly take the risk. If crimes only happened when there was a 0% change of getting caught there would be no crime.
I'm ready to watch that movie
That's not true. I surely don't trust banks, but at least they're regulated to the point that they have to come up with some legal pretense for seizing my funds. A bodyguard is ostensibly a person who I've incentivized more than the competition to not harm me, and who I probably form a relationship with over time. None of these things are true of Amazon.
> Stealing data from a customer paying for hosting would be _very_ different, and much more scandalous, than identifying trends on a competitive marketplace and taking advantage of them by launching competing products.
What part of using data that you have on your competitors but they don't have on you, to sell competing products on a platform where you don't have to pay fees but they do, sounds like a competitive marketplace?
This is true, but it doesn't have to be this way [1].
Now things may have changed since then, but I'd imagine it's not yet gotten down to 1.X inefficiency multiplier regardless of the FHE scheme you're using.
(Well, it seems like SGX is insecure right now with all of the CPU vulnerabilities, but in principle it may be fixed in a future generation and be well-suited for this.)
The fact that you wouldn't have to trust your host specifically could have a real decentralizing effect for cloud hosting: people would be able to run stuff on any cloud host without needing to trust them much. If you just wanted compute power and didn't care about strong uptime/connectivity, you could even safely rent cheap VMs on computers of random individuals.
AMD SEV, on the other hand, is exactly that.
As an aside, Amazon competitors like Walmart typically require their suppliers to host data on a platform other than AWS if they want access.
In the past, AWS has used the data from third party hosted services on AWS to build a similar service and in fact start poaching their customers.
Source: I used to be at AWS and know the PM & his manager who built a service this way. I was hired on that team.
He wrote this: https://www.nytimes.com/2019/12/15/technology/amazon-aws-clo...
Edit: fixed a typo
You might have a family to protect. A home to maintain, etc. I understand. It's scary. But the world doesn't and cannot change for the better if we let corporations bully us into silence. The world will and does change when brave individuals, with the support of society, stand up and blow the whistle.
But yes, I would be happy to contribute to a support fund to support such individuals.
>But yes, I would be happy to contribute to a support fund to support such individuals.
cool you can start by donating to absolutely any charity in need right now.
Even if their claims are true (which I certainly don’t believe they are), you’d be more likely to get better uptime than EC2 with a small on-prem setup through dumb luck rather than through deliberate planning. Something still has to go wrong for you to have an outage, and you’re more likely to get an incredible lucky streak than you are to outperform their entire AWS infrastructure capability with a few people and half a rack of servers.
2011 April 21 Outage
2011 August 8 Outage
2012 June 29 Service disruption
2012 October 22 Outage
2012 December 24 Outage
2013 September 13 Outage
2014 November 26 Service disruption
2015 September 20 Outage
2016 June 5 Outage
2017 February 28 Outage
2018 March 2 Service degradation
2018 May 31 Outage
And yet, a couple times a year perhaps, we have discussions right here on HN about the latest AWS outage that took down half the Internet.
That's not even considering the potential impact to software development and innovation that we get with commodity cloud services. This is hand-wavy of course but I'd stick to it.
Drop the servers in HA sets of 2-3 nodes across 3-4 regions, anycast your service endpoint from each cluster. The hardest thing to replicate without AWS is the 6-7 figure bills.
If some sanely architected code was all you needed, then you’d expect at least other cloud/IaaS providers to be able to match AWS service levels. Which they can’t, and which some little software shop most certainly cannot either.
Personally, I wonder if that isn't an emergent property of a lot of people trying to scale at once.
Equal protection or application of computer crime law (perhaps, any law) in the USA is a fiction. It would be practically illegal to invent and run a web spider today, for instance, if they didn’t already exist as a concept. (France recently decided this was true for news link aggregation; Google must pay the newspapers for reproducing their headlines. I’m glad hosted RSS readers aren’t outlawed so far, but under these sorts of restrictive legal interpretations you could see how they might be. Google doing AMP, of course, gets a free pass.)
If you don’t believe me about the web spider thing, try making a complete download of Twitter for the purpose of making a tweet search index and see if you get to continue owning your house. (My theory is that Clearview is allowed to do it for Instagram because they’re using the database to provide services to law enforcement/military, so those groups want it to continue to exist free of prosecution.)
Bummer that actively collaborating with violent types like pigs and military seems to be the only way to avoid jail if you want to build large novel data systems with interesting public datasets today. This sort of freedom to experiment with new/neat algorithms over published documents got us Google; today these same companies will get you raided if you dare download/index their data. (Facebook’s idea famously started out scraping public yearbook photos. Try scraping Facebook now.)
one small counterpoint: https://www.eff.org/deeplinks/2019/09/victory-ruling-hiq-v-l...
RIP aaronsw
Now, indiscriminate access to your content might violate whatever commitments Amazon made to you in their terms of service; I have not read them for a long time and can't remember what the language is specifically. But that would not be a matter for the FBI.
AWS terms do not assign their customers any rights to any physical computer. And the AWS customer agreement gives Amazon the authority to access your data for certain purposes.
I'm not sure I've ever heard of anyone prosecuted under the CFAA for accessing a computer that they physically own and physically control. AWS is a service, not a computer rental.
> We will not access or use Your Content except as necessary to maintain or provide the Service Offerings, or as necessary to comply with the law or a binding order of a governmental body.
The CFAA uses wording like "exceeds authorized access", which Amazon would absolutely be guilty of if they went into your database to spy on your product listings.
If they could go after Aaron Swartz for using authorized access in an unauthorized way, it seems likely it could be applied here.
Would a judge accept that argument? From me? No. From the lawyers Amazon can afford? I wouldn't be comfortable betting either way.
In this case, Amazon fully owns, possesses, and operates the "protected computer".
You'd have to successfully argue that Amazon fraudulently accessed their own computer. It might be possible, but I'm guessing it'd be a first.
The difference in Aaron's case is huge: he didn't own the computers that hosted JSTOR.
> The difference in Aaron's case is huge: he didn't own the computers that hosted JSTOR.
His access was authorized, though. They still threw CFAA at him.
You have to "exceed authorized access to a protected computer"
The CFAA is not a data protection law. It is a computer protection law.
> In practice, any ordinary computer has come under the jurisdiction of the law, including cellphones, due to the interstate nature of most Internet communication.
Maybe it is possible, but the consequences to answering 'yes' to this is pretty scary.
If I'm renting an apartment, my landlord can't install a camera in the bathroom, even if they're the owner of the building.
Ownership doesn't change the fact that the law says "exceeds authorized access". Amazon agrees to only access the computer I'm renting from them in very specific scenarios. If they violate that, it looks like a pretty clear CFAA violation.
> Amazon agrees to only access the computer I'm renting from them in very specific scenarios.
AWS provides compute services, they do not rent computers. They make this clear in their terms.
They demonstrate that legal ownership is not the same as the legal right to do whatever you want with what you own.
> AWS provides compute services, they do not rent computers. They make this clear in their terms.
Good luck hoodwinking a judge with that argument.
Which one do you rent?
Where is your rental agreement?
When did you first take possession?
Of course there are other reasons to use physical servers.
The one point of solace is that there's a lot of competition out there for web hosting.
Safe to say they are not on Azure.
There are ways that you can use AWS that Amazon would have no way to access any of your data even if they wanted to.
Is it worth the extra effort and moving already functional servers to do so?
You may trust them not to abuse hypervisor access, but they still have network “meta” data - it could tell them how many transactions clear against credit processors (though not the actual amounts if encrypted), a good idea general distribution of page views With respect to time and user ip (though not the exact pages), times of day, demographics of users (Geo locations and ISPs, for example)
If you don’t trust them not to peek at what they can, don’t use them. He is perfectly right.
There are other cloud providers who aren’t competing with B&H and would be a better choice. But amazon is a direct competitor to B&H, even if they do have an IT barrier - they cross subsidize; any $ paid to Amazon helps it against B&H.
Please explain, as I'd like to know how.