Maybe the bigger you are, the more you think about security, but the bigger you are the more difficult it is to protect yourself
Now for a BUSINESS, I could see the advantage in less maintenance cost and being able to spin up/down services easily. It is easier and that cost is measurable (up to a point; when you get big enough AWS costs become obscene compared to self-hosting. I've been at more than one shop that moved things back on-prem to save money).
I’m actually dealing with an issue where one RDS instance in AWS costs more over three years than the entire infrastructure and software investment did on the on-prem.
Most of the projects I work on now have 1-2 IT people supporting 100 devs.
Will non-tech-competent companies without well-staffed security teams make it? How much individual, private digital data is likely to make it as long as say, a vellum manuscript?
The question is if any of these leads to lateral movement and access of sensitive information or modification of data and stuff. No company is required to tell you about every single piece of malware they find in their networks - unless something "bad" happened. Maybe we should require more transparency in general.
I guess investigations will show what happened or is happening still.
A cloud hack like the parent poster talks about assumes that you get access to the hypervisor layer and can look at the RAM of the guest machines.
This is not inconceivable. Rather, it seems quite reasonable given the complexity of hypervisors and the prevalence of CPU architecture bugs that makes these attacks easier.
This is what https://en.wikichip.org/wiki/x86/sme is for
Some of that is on AWS for initially making the defaults too open, but at the end of the day, S3 was doing what it was told.
Is there some case where S3 was locked down, and the data still leaked?
What? Their internal build system was comprised and the password for the FTP that hosted their software updates was "solarwinds123"
This had nothing to do with the cloud/a issue with a cloud provider.
Secrets in a public github repository is a leak, in the cloud.
Someone uploading their secrets to GitHub has nothing to do with the cloud and everything to do with the incompetence of the people using it.
"This is the clouds fault because one of our engineers made a mistake and 'the cloud' didn't stop them!" does not really hold up.
It's an untenable problem for organizations of any size. There aren't enough man hours to reverse engineer and vet all the third-party software that any sized organization uses. There's no community will to force vendors to do better either.
We need something like an Underwriters Labs for software. It probably will take the insurance industry coming down hard for things to change.
Amazon, G and MS generally do.
I believe that whatever data you have, it's more secure on AWS than anywhere but your hard drive not connected to the internet.
If the [inter]national infrastructure goes down, with the firmware on every device on every internet-connected computer bricked at the same time due to a large-scale cyberattack (perhaps followed by a military attack a little while later), we're f-ed.
All this would take is:
- One zero-day each on Windows, MacOS, and Linux.
- Nation-state level resources to create a bricking firmware update for all commonly-used devices.
- Nation-state level resources to create a spreading attack for all major routers and network devices.
- Nation-state level resources to deploy this rapidly enough that response systems can't respond.
With 200 nation-states, it's perhaps just a matter of time....
(And yes, there's a lot more i's to dot and t's to cross, but I think they're all doable, with nation-state level resources)
I think this is more "movie plot", though. "Smart Grid" security has gotten tons better than it was at the start. A lot of very security conscious and smart people have been working on it.
(1) Tank the economy
(2) Likely, be doable with resources totaling in the single-digit million dollars
Modern wars are largely about industrial capacity.
But if it is equally easy to compromise the grid, why not do both?
This may sound like a movie plot, but so did the invasion of Poland at the beginning of WWII, the attack on Pearl Harbor, nuclear bombs on Japan, the rape of Nanjing, or many other actual events which Actually Did Happen.
We tend to underestimate the impact of rare events: our brains are conditioned to discount anything which happens once or less than once per lifetime. That's likely why humanity will kill itself at some point.