Interview with an anonymous AWS cybersecurity engineer
logicmag.io
logicmag.io
A few sentences that stand out:
> If you have a ton of data in your data center and you want to move it to AWS but you don't want to send it over the internet, we’ll send an eighteen-wheeler to you filled with hard drives, plug it into your data center with a fiber optic cable, and then drive it across the country to us after loading it up with your data.
> Q: I know there have been a number of collective actions among Amazon warehouse workers around the issue of safety during the pandemic. > A: (a series of measures implemented at Amazon)
> Internally, people say, “Oh, we’re probably better than our competitions, or other warehousing and logistics companies.”
> Q: Has Ring brought Amazon into much closer relationships with law enforcement? > A: it would really surprise me if any of those relationships were the result of the Ring acquisition [...] I think Amazon also kind of backed into that situation. We only realized after the fact that we had all this data about who was coming to people’s front doors.
It's been established that "selective whistleblowing" articles are deemed to be more trustworthy than official marketing statements. Therefore, it would be foolish for corporates to not exploit that to their advantage.
The writer is a faculty associate at the Berkman Klein Center at Harvard Law, which is an organization I have tremendous respect for, so it's really a shame that they were naive enough to publish this.
> So if you have cancer and you might die from your cancer, we won't help you get treatment
It just feels.. off. I wouldn't go as far to say the person doesn't work at Amazon at all and instead wants to jab at them but I'm definitely thinking it loudly
If you get cancer or any other major medical catastrophe, Amazon won't do anything to you if you're a part time worker without health insurance. But even if you don't have the health insurance, Amazon will provide support if you catch COVID. Because it's good business to not have one uninsured person to expose an entire shift to a highly communicable disease.
With the exception of it being a whistleblowing thing you don't often see jabs like that -- especially jabs at departments the person has no involvement with. Also if it is whistleblowing it's more a "they" than a "we" thing
No names. No contact information. No accountability.
This isn't journalism. It's a random blog that claims to put out a print edition three times a year.
Interesting things he didn't really talk much about: Alexa (there was 1 like 1 very superficial reference to it), Kuiper, and others.
I don't think this is a PR piece, and most likely it is not approved by the company (the reference about Jeff's Sex Life would've been removed). This does feel like a real view from an insider, it's very opinionated, and not all of it is right.
I'd guess the building is named after the Library of Alexandria – one of the largest and most significant libraries of the ancient world – and not because of a god complex as the story implies.
I don't see a writer listed. What am I missing?
(Disclosure -- I'm a BKC fellow this year)
As for your comment about the writer, the entire website feels very "off" to me - no author listed, no "About" page with names/links, nothing to give this credibility. I did see the link to the cofounder's Twitter page, so at least there is someone behind it, but it is pretty well hidden.
Caesar wrote his books in the third person as well. Bezos seems to me like the kind of guy who'd do that.
Also I'm not too familiar with how Bezos writes, but from the few interviews of him that I've heard, it sounds a lot like him to me. See also this letter... guess the author :). https://twitter.com/LettersOfNote/status/923473337115914240
Prime Video, for one. Jeff loves Prime Video because it gives him access to the social scene in LA and New York. He’s newly divorced and the richest man in the world. Prime Video is a loss leader for Jeff’s sex life
errm... That should be on their SEC risk report
> If you're working in Seattle for Amazon and you're good at your job and you want to leave your job tomorrow, you have far fewer opportunities. Where are you going to go, Microsoft? There's not nearly as much mobility. So I think a big part of the reason we have less organizing [than Google] is that people are more afraid to jeopardize their jobs. If you want to stay in the Northwest, you keep your head down.
Is that... really how people view Seattle? Feels like there's always a zillion companies hiring here.
I don't buy the BS from the interview/blog article.
No Amazon engineer I know was worried about leaving/loosing their job. All but one said their engineering culture wasn't fun to work in, and they all left before fully vesting... so i wouldn't say they were held hostage in any way.
source: work at MS
Wtf is this article even about, am I reading a random lunch conversation between old friends that was made more interesting by the guy coincidentally working in security (a hot topic) and being made anonymous (so that people would assume shocking secrets are to be revealed inside)?
this section is just nonsense. So the crisis happens then devs in "developing countries" become cybercriminals ? total bs ...
Sounds like PR fluff. Maybe the crappy nation states have poorer posture, but decent nation states tend to have decent knowledge of security principles, decent isolation of data and tenants within networks, various physically enforced unidirectional links and decent actionable threat intelligence, none of which are necessarily evidenced for Amazon by the interviewee. Additional evidence to back the claim would have been nice. I am not saying nations do not make security mistakes, they make plenty, but I am not convinced it is due to a somehow inferior or less sophisticated approach.
"They might, but ultimately the security standards of their data centers are always going to be lower than those of a cloud provider like AWS. A cloud provider has many tenants and they can have economies of scale that let them have more sophisticated security systems than someone fully managing their systems in-house."
Interestingly, the economies of scale argument, while true, cuts both ways, because there is an economic limit to securing shared infrastructure. The business model of AWS and other CSPs is to multiplex access to shared resources, thereby introducing multi-tenancy issues as well as putting more eggs in the one basket, which is much more lucrative for an adversary to target. I think a mature cybersecurity engineer should be aware of the tradeoff, seems this one is somewhat biased.
I am not sure if it is intentional, but marketing a big truck with guns may be capitalizing on conflating security with the perception of security. Can someone please explain why the truck being giant adds to security? Is it harder for it to roll over on the freeway and cause bits to spill?
"The rumors that I hear, both internal and external, are that we're very seriously interested in acquiring post office real estate. The reason why the post office is valuable to privatize is because of their real estate holdings. They have great real estate in every downtown of every city in the United States. Amazon may be interested in buying all of the post office locations, and we have the cash to do it. So why not?"
Chicago's Old Main Post Office (so massive that it has an interstate highway running through it and 18 train tracks under it) was recently redeveloped for a bunch of tech companies.
FTFY
This should be rephrased as it's only for consumer product purchases
Neither company is private. They’re both public companies. This is the second sentence in the article. The rest of it sounds made up
There are things I am not comfortable disclosing in public; however, I can tell you that most of what's written is incorrect, guesswork, or distorted from reality - e.g. the "origin" of Amazon, or the origin of AWS.
I've read enough to know that this piece is not worth reading in its entirety.
Of course, the anti-Amazon mob will just call this a PR puff piece. But it doesn't read like it to someone who actually works in cybersecurity at AWS.