A New Approach to Amazon EC2 Networking
aws.typepad.com
aws.typepad.com
I'd bet they're still significantly in the red every year. Eventually they'll get big enough to start skimming a few points of profit off the top. Margins will always be low because that's a huge part of their strategy.
I use Amazon because of it's convenience and brand name, but I've always seen it as having a decent premium.
Anyone can buy $100k worth of servers and $10k/mo in bandwidth and easily beat AWS pricing. That doesn't make it competitive with AWS though.
AWS is providing world-class network/server infrastructure as a commodity, which is decidedly different from the kinds of infrastructure most hosting companies have.
I actually think AWS is profitable and while they might not have recuperated their initial datacenter investments, they do cover the accounting depreciation (which is all that matters).
Saying that Amazon sells you customer service seems entirely unrelated. Yes, the might have better customer service and they might have more things (EBS, Route 53, etc) but they certainly do not undercut their competitors price-wise.
Even if you amortize the cost, it's amazingly expensive.
A while back I recall Amazon saying that this was possible. We're looking into the possibility of moving to the cloud, and on first look our PCI guy saw some problems. We've just started experimenting so could easily have overlooked something, but these were the stumbling blocks we saw. It looks like these new features address 2 of these 3:
• PCI requires limitations be based on outbound traffic from the cardholder environment. Amazon only allowed inbound filtering. Now they have outbound filtering, so this may be no longer problematic.
• PCI requires internal machines to be placed on internal private networks using NAT. Amazon did not support NAT. Now they do, so this block may be gone.
• PCI requires that all traffic be monitored with an IDS in the cardholder data environment. It doesn't appear possible to do a central monitoring machine with IDS in EC2.
However, when it comes to actually doing that things seem a bit less clear. For instance, outbound filtering is a requirement, but Amazon just added that, so how did one satisfy that requirement before today?
It's possible that we've got an overly strict PCI guy.
Anyway, this particular issue appears dead now, as these new EC2 features add outbound filtering.
Still, it's unnecessarily complicated and as you say, a resolved issue now. :) The new features announced fits PCI needs quite well. I haven't looked into the IDS issue you mentioned in your first post yet, but I hope it's possible to resolve somehow or get around with compensating controls.
(Disclaimer: I'm no PCI DSS expert, just an unlucky engineer trying to make a compliant system.)
Congrats on shipping, guys.
I'm as interested in the AWS team as I am in any startup that exists today. I'd love to read about the tech challenges/team make up, etc. Is there any good coverage of this?
If Bezos's personality is decidedly noncorporate, so are some of his ideas about how to run a large organization. One of Bezos's more memorable behind-the-scenes moments came during an off-site retreat, says Risher. "People were saying that groups needed to communicate more. Jeff got up and said, 'No, communication is terrible!' " The pronouncement shocked his managers. But Bezos pursued his idea of a decentralized, disentangled company where small groups can innovate and test their visions independently of everyone else. He came up with the notion of the "two-pizza team": If you can't feed a team with two pizzas, it's too large. That limits a task force to five to seven people, depending on their appetites.
I first tried Rackspace Cloud, who would send me frequent marketing-style e-mails with stock photos of intelligent-looking office employees, ask me to participate in raffles, and other nonsense that I would quickly filter.
I much prefer seeing new feature announcements from AWS in my inbox! (And on HN.)
AWS Elastic Beanstalk, Elastic Load Balancing, Amazon
Elastic MapReduce, Amazon Relational Database Service
(Amazon RDS) are not available for use in a VPC at
this time.
http://aws.amazon.com/vpc/#legal