GCHQ award spy agencies cloud contract to AWS
theguardian.com
theguardian.com
- the contract is with a UK AWS subsidiary
- uses UK based datacenters
- is subject to appropriate oversight by UK nationals
- excludes really sensitive intelligence data
Sure this adds a dependency on a non UK company but is it a security risk - possibly not. Is GCHQ dependent on US / Taiwanese manufactured semiconductors? Is that a risk - maybe but it’s a manageable one.
Have you seen the nationals allegedly running our country? We're screwed.
- This is an air gapped environment with effectively a unidirectional flow of software bits into the place at infrequent intervals
- Only cleared UK personnel operate it and the regular AWS workforce has no access except for escorted sessions in rare cases.
- No data leaves, i.e. not even operational logs etc
That's the standard for such installations.
https://www.datacenterdynamics.com/en/news/nsa-awards-secret...
This is lucrative for Amazon, and likely convenient for the Five Eyes and their data sharing ambitions.
Readers of that book treat any imperfection in your mental health---for instance, side effects of a pill a patient is taking against their will, such as temporary brain damage, which can easily make said patient seem off kilter---as a plot twist, like "oh, he's not 100% sane like I am, it's like in the Catcher in the Rye, my favorite book, in the end you find out it was all lies, and that's what this is."
Factually, in the Middle Ages, fools (the mad) were considered more truthful, and their testimony more reliable, than that of the sane. Recall the saying, "only a fool can speak the truth in court." In part this is because they had a harder time keeping their lies consistent, so they had to just tell the truth.
I would burn "the Catcher in the Rye."
At $6,000 per capita, we could just about expand Medicaid to cover half of the population with our existing annual healthcare outlays. That would solve a huge number of problems for the US in healthcare.
The reason I wrote that specific comment, dear pc86, is because there was wide discussion in this thread about Britain not being able to do their own version of AWS in-nation or not being able to do it cost effectively. So it only makes sense we, the US, might consider returning the favor with Britain on something they do far better than the US does (cost effective healthcare). Especially given they're an exceptionally important economic partner to the US and Amazon getting that contract is valuable to a US company.
Did you happen to see Zenst's comment? They mentioned "The Catcher in the Rye," the audacity. What does that have to do with datacenters or software?
"Ensure Cloud Sovereignty" ... "...centralised, security-cleared, UK-based operations team..."
This could be a commercial entity that is owned by the government.
After all - data held in a country is subject to the government of that country being able to demand/obtain access.
I am curious how it would work using the AWS tech that is probably built by a lot of non UK/US citizens. Maybe the UK will allow work done by US citizens.
But AWS and MS have both deployed dedicated DCs for sensitive UK Government cloud requirements: https://docs.aws.amazon.com/whitepapers/latest/data-classifi... https://news.microsoft.com/en-gb/2017/09/21/police-uk-reache...
Those DCs can be audited in a way that the CSPs don't generally allow for "normal" customers.
> There is a specialist UK Government IaaS provider:
So, no?
Unless you're interpreting the question as "does anyone that isn't AWS provide all AWS services" which is obviously not going to be true.
AWS is probably genuinely the best tool for the job here.
The point of the cloud is treating it like a commodity.
Unfortunately this smells very much like favoritism.
Is it? The article is pretty unclear on what exactly GCHQ is trying to achieve (not unusual for intelligence agencies of course!) I think it's hard to comment on whether awarding the contract to AWS was reasonable when we don't know what any of the requirements are.
Because it's really hard to train technical staff, certify the security of, and harden your attack vectors on one platform let alone doing it for 10 of them. These providers that handle gov data generally have isolated data-centers with more stringent security protocols, like making every employee have a security clearance. Doing that for more providers would increase costs exponentially for very little gain.
It's like having your Windows server department, Linux department, mainframe department, SQL server admins, DB2 admins, Postgres admins, NFS team and SAN team.