You should have picked a different analogy.
In the end AWS S3 is just distributed file storage.
Setting up your own servers was not a bottleneck to the generation of internet companies that preceded AWS, and time has only made hardware cheaper, bandwidth more affordable, and OSS higher quality and more plentiful. It is easier than ever to host your own services, AWS just makes it cheaper up front thanks to their massive scale.
Point being, people aren't choosing AWS because AWS solves a problem they're incapable of solving, people are choosing AWS for pricing flexibility and faster time to market.
So when you say "what AWS does was previously done by every single IT department at every company across the globe" yes sure but (1) it was done worse in many cases, with data loss or significant downtime, and (2) there were fewer such companies by magnitudes, because of the cost barrier.
What AWS did was take a costly process, done inconsistently and to varying degrees of correctness across the business world, and make it available to everyone at a very high quality, with a innovative pricing schedule.
S3 has eleven 9s of durability. That alone is bonkers. Sure, let's say you replicate that and staff it up to keep it working ongoing.
I didn't say "replicate S3", I said "replicate a significant portion of AWS". A lot of the value of AWS doesn't come from using _a_ product, there are alternatives for most of what they offer, it comes from having the whole ecosystem of tools integrated and available in one place.
So now you need to go build out a highly available, redundant queuing service like SQS that supports FIFO delivery and up to 20k inflight messages.
And a highly available, redundant notification service with integrations not only with the web/email/etc but also SMS.
And a geographically redundant database service with multi-master, instant snapshots, point-in-time restore, etc, etc.
And... well, pick whatever other handful of AWS services you're using in your specific use-case.
And wrap it all behind tools for management. And hire a whole wackload of ops staff to keep it all going. And pay 10x as much because you don't get the economies of scale that AWS does.
I'm not ignorant of the difficulties in setting up generation and storage for electricity. But I'm also not ignorant of the absolutely massive task it would be to replicate AWS if you're it for more than a really expensive VPS hosting service. I would 100% choose to work on off-grid electricity generation before rebuilding AWS.
You entire take is based on the idea that AWS replacement has to be superbly reliable and scaleable, while your grid replacement does not.
Lets compare like for like, your grid replacement has to have redundancy so that generators can be repaired without power loss, it has to support megawatt scale spikes in demand in case several friends with electric cars come to visit, it has to have mean time between failure measured in years, withstand extreme weather, and be renewable. Also you need to have black start capacity and logistics to replace equipment promptly when it fails.
How is the cost for that going to compare to using the grid?
If they want utility levels of trust they should get nationalized.
Because if Amazon retail, which sells stuff, is looking at sales in their channel, well, that's sneaky but the entire retail world is sneaky.
If Amazon AWS is caught snooping at private AWS data, which contains HIPPA-compliant health info, financial records, government data, and some of the most sensitive data imaginable ... then they are toasty-toast.
I think the same thing would apply to Google. GCloud is different than Search etc. if that firewall breaks down that business will crash.
Why? Says who? Who or what would make them 'toasty-toast'? The toothless regulators? Feckless IT managers who make purchasing decisions? Impoent developers whining on hacker news?
> if that firewall breaks down that business will crash.
Not sure why you're so confident about this.
a) GCloud is a distant 3rd place competitor in the cloud market anyway.
b) Google's real business is ads, and at some point the numbers might make sense to decide it's worth cannibalizing their dying cloud. (Especially if they're going to pull the plug anyway?)
c) None of the other data scandals has even slightly dented big tech.
Second, because IT managers and executives would freak out everywhere, with legit cause. Nobody on the planet running an SaaS would want AWS to be using their data.
Third, it's probably illegal, so there's that.
Finally, the PR fallout would be huge.
If Blue Shield had a major client leak of HIPPA info, and it was because 'AWS staff were looking at it' it would be a big deal for AWS. They would have to prove to everyone that it was just a few bad apples etc..
Most of the other scandals have not dented tech because they are not really scandals. If FB has a breach and some consumer email addresses get leaked ... well that's not so bad. If AWS is looking at BestBuy AWS data, then BestBuy will sue and drop them, and others will follow suit.
Remember when we though that whoever is in charge would be Toasty-toast it it turned out that Government was spying on innocent people without due process?
Or if an aircraft company knowingly produced unsafe aircraft and killed 300 people as a result?
For the past 10 years I have seen countless corporate or breaches and fuckups, and one thing they have in common, there seem to be no consequences for those in power
It's not 'we' thought the government would be in trouble if they were caught spying, it's 'some' people. Most people have more nuanced views. Especially in areas of national security most people accept some degree of oversight, so the issue then becomes a matter of details. What was the oversight? What are the material repercussions? Who is harmed? How? All of those things add up in complicated ways among the general population.
The Boeing issue is also complicated. These are not black and white decisions, and just because there was an Engineer 'who said something was wrong' doesn't always help, because there's always a person of credibility that disagrees with systems, many of them are safe. Boeing has paid a huge price for their screw up, with grounded fleets, cancelled purchases.
When Facebook does bad stuff - remember that consumers greatest power is the choice to not use Facebook. So either people continue to use it - or not. Apparently they are, so that's a measure of their real concern for their data given the breaches.
If HIPPA information was looked at by AWS, then there would be lawsuits immediately for example, there would be an investigation and if it was 'just a guy' then I think AWS would be ok, but there would be a lot of scrutiny.
But if there was a whistle-blower at AWS who said 'people are looking at sensitive data all the time' then it would be over for them. While individual consumers may not collectively have any real power to do serious damage, big companies do.
Put yourself in the shoes of an Exec running on AWS infrastructure: all of your most sensitive data leaked, possibly to potential competitors? So the issue is raised far beyond IT personnel etc..
Just like you'd ground your Boeing jets if there were a safety issue, you'd probably move away from AWS.
At least PCI-DSS certification (I don't know about HIPAA) further involves annual audits to make sure that certain proactive things are being done as well, specifically including things like data access logs. Those audits aren't as comprehensive as they ought to be, but they'd catch something egregious like marketing people looking into data owned by AWS customers.
I'm pretty sure (though much less than the above) that this would also be a de facto GDPR violation, meaning that nobody who wants to do business in Europe could safely use AWS anymore either. Amazon itself uses AWS and wants to do business in Europe, so that's a pretty good incentive.
We had to deliberately downgrade certain software to "approved" older versions and temporarily close some ports while they ran their scanning utility on our servers. After they rubber-stamped it, we re-upgraded and enabled whatever we needed to run again.
They certainly would not have been able to detect if data center technicians (this was pre-cloud) were accessing our data behind our back. Maybe some companies take the PCI certification process more seriously than my previous employer did.
In those cases they mostly looked at traffic volume, etc., not private customer data, but I don’t have any insight into which ethical lines they will and will not cross.
What, you mean smart? A lot of data centers do exactly that. SevOne has at least five Bloom Energy H2 fuel cells that run the whole building because they can't afford any downtime.