The titanic (cloud) is sinking, the engine room is already full of water, but the people in the ballroom (execs) are still celebrating with champagne, even though the warnings have been called multiple times.
The titanic (cloud) is sinking, the engine room is already full of water, but the people in the ballroom (execs) are still celebrating with champagne, even though the warnings have been called multiple times.
I'm not saying cloud computing is the solution to every problem, and nor should it be, but calling it a sinking ship is simply absurd.
Frankly, I grow so tired of people thinking everything is a boolean choice. The real problem with the cloud is people who see things as binary statements: "cloud is cheaper", "cloud is more expensive", "self hosting is easier", "cloud is easier", "cloud is more secure", "on-prem is more secure", etc. All of those statements are true just as all of those statements are false. The reality is far more nuanced and it depends entirely on the constraints of your business at that point in time. Such as what engineers / skill sets do you have on your team? Capital to buy hardware, your physical location, the product you're trying to build... etc.
But the problem with nuanced arguments is they're subjective to the immediate problem you're trying to solve. So you cannot debate them with other people as those other people are trying to solve different problems with different teams and different tools. And thus we end up with people posting bullshit blanket statements like "the cloud is a sinking ship" or the linked article that boasts that the cloud is less secure.
Cloud is centralizing. Centralizing, instead of distributing, is bad.
Centralization broadens and expands the attack surface and creates a honey pot for attackers.
This isn’t hyperbole nor is it alarmist. This is reality playing out before us in real time.
Fragmentation creates different problems than centralization, but it isn't a magical bullet either. Depending on your resources, you are far, far better off trusting even Microsoft than trying to come up with your own security implementation.
There is no consensus.
But, that's with every industry, every field, every platform.
Some warn, others ignore.
Wanna bet who's right?
I've been doing this stuff for longer than a lot of people on here have been alive and the biggest risk is always your weakest link. The weakest link in most companies isn't the cloud, it's the engineers deploying to the cloud. That weak link exists regardless of whether those engineers deploy to a centralised place or on-prem.
Is there an additional risk having something centralised? Sure. But in the vast majority of use cases, that risk is going to be marginal (and for those types of businesses where it is an unacceptable risk, they are largely not using public clouds for exactly this reason).
And we are back to my point about these conversations being nuanced. A security team, if they do their job correctly, doesn't just make blanket statements like "centralised systems are insecure" -- instead they identify the risks and develop an IT strategy based around which risks a business is willing to accept and which are not.
Some warn, others ignore. Is true. It's true for every industry, every walk of life, in every country, on the entire planet.
Experts, though, when have they agreed on anything, in any field?
One must ascertain for themselves which authoritative sources can be relied upon. The experts that warn of centralization are authoritative and masters in their fields.
Centralization in any other area of life tends to be bad for citizens, so I ask you this: Why would centralization lead to MORE security, or MORE benefit to the users and citizens of the world?
I'll wait...
That’s not what they said
> Centralization in any other area of life tends to be bad for citizens, so I ask you this: Why would centralization lead to MORE security, or MORE benefit to the users and citizens of the world?
I had already addressed the point about centralisation and risk. This additional question you’re raising is, at best, a straw man argument.
If you go back and read, and I mean properly read, pause and think about the comments being made, you’d realise that we aren’t saying risk doesn’t exist. We are saying the reality of that risk depends on numerous factors specific to each business, project, and even team. Thus you cannot distil “the cloud” down to a single truism such as what you keep trying to do.
Bloated security theater being profitable also doesnt help. One example is smartphones as TAN generators for online banking replacing TAN lists. While you can now charge customers per SMS, the second factor got quite a bit more easy to attack.
I don't see the argument here. CISA posts issues they find, are they intended to be comprehensive?
This is in addition to a lot of government agencies sitting on, and investing into the knowledge about vulnerabilities. Some of the more public ones getting fixed doesnt change the overall vulnerability of the system. There is a clear incentive mismatch. One cant pretend that those vulnerabilities are "safe" due to only spooks knowing of them. If you can find them, so can others. Especially if you are actively exploiting them.
I would argue that this shows both an unwillingness to accept improvements in security as well as actively degrading the current state. And this is before talking about governments actively adding vulnerabilities, which now even possible by law in some jurisdictions.
The Machine Stops by E.M Foster
https://web.cs.ucdavis.edu/~rogaway/classes/188/materials/th...
for some, this sounds like a nonsensical choice. for others, a defining moment of leadership.
>How a baker survived the Titanic sinking by getting really drunk
Bottoms up!