The US is far ahead of most countries when it comes to government use of the cloud. Other developed countries often learn how to do it from the US but are less comfortable with the technical requirements, which slows down adoption.
Not that they're the only ones. Israel has been busy stuffing investment cash into the pockets of Unit 8200 members so they can found security software and service startups coughSnykcough
It’s the best of both worlds, they get the decades of research Google has put into systems engineering and fault tolerance while retaining the security of having their own servers.
Very few actually qualified and capable techies here trust any of the US-based cloud providers.
https://aws.amazon.com/govcloud-us/?whats-new.sort-by=item.a...
https://learn.microsoft.com/en-us/azure/azure-government/doc...
The government doesn't have leverage. The government is Amazon and Microsoft's leverage against others.
I make the parallel with "gold." Whoever has your gold, got you by the hanging spheres.
Given the importance of data today, I am baffled common citizens are not familiar with the "Data at rest" principle.
If a country's citizens want to give away their data, it's well within their right to do so. At most, the U.S. Government should educate about it, much like tobacco dangers.
Having that said, U.S. citizens with clearance and/or government employees should be subject to data loss prevention measures, like they already do[0].
I'd be forward for a ban if it was an issue of public mental health, but the U.S. Government cannot take that angle because they'd have to kill Meta Platforms as well. They know they can't, Meta lobbyists will not allow that.
But restricting TikTok based on data control and free speech liberties, that's overreaching. I've already seen TikTok videos of people saying they'd stamp their U.S. passport on the forehead and give it to Chinese ByteDance rather than use Instagram. It is well within their rights to do so if they so desire.
--
[0]: https://www.pbs.org/newshour/politics/why-tiktok-is-being-ba...
Ban TikTok? Do whatever, I don't use my account. I deleted the app long ago.
Why do you do it? Fight that tooth and nail. Do it for the right reason and be consistent.
That should scare everyone given his propaganda machinery aimed at elections he does or doesn’t like
"other voices" is a joke given how much censorship there is on twitter
See, parent is right? Safe/not safe dichotomy helps nobody
To be clear, this was 10 years ago so things may have changed. Also, my task was memory bandwidth limited, where even changing the memory access patterns slowed things down by 10% or more.
Alright so get a magical amulet.
If China and Russia can somehow solve the issue and manage their infra, I don't see why EU, for example, can't.
It's better to have at least partially protected your whole government and citizens data than having it handed directly to the foreign intelligence in bulk. That's the question about political will, we don't talk about average Joe here.
Except if any of the bits are flipped you're f-d; especially so if your adversary is a nation.
I think it's obvious that some secrets should be kept. It makes little sense to expose our nuclear secrets, counter espionage, or ongoing investigation efforts. But how far does or should that extend? Should everything the NSA/CIA/FBI/IRS does be secret? Should they stay secret for years or decades or forever?
IMO, the US goes too far in it's secrets. Stuff gets classified that just makes the government look bad and that's dangerous.
And that's where I'm somewhat less concerned about putting US secrets into the cloud. Sure there's highly sensitive stuff that shouldn't go there, but there's also a lot of stuff that shouldn't have been a secret in the first place.
GovCloud claims that it's used to "manage sensitive data and controlled unclassified information (CUI)."
I don't think the US government is dumping classified info onto corporate cloud environments judging by this description from GovCloud. But there's plenty of info that's sensitive but unclassified and the government does need to function in a lot of ways that doesn't involve state secrets.
https://aws.amazon.com/govcloud-us/ for more of a description of what GovCloud actually is.
There are cloud environments specifically for classified info:
https://aws.amazon.com/federal/secret-cloud/
https://techcommunity.microsoft.com/blog/coreinfrastructurea...
For the former, confidential compute is far enough along that this data can in fact be secret from the hardware owner. This is vital even for on-prem hardware -- IT folks and techs with physical access shouldn't have access simply due to proximity.
For the latter, sure, but this is very expensive. It goes well beyond owning the hardware.
This fact conveys information. Namely, how tightly bound these supposedly independent services like AW GovCloud are with the government itself.
Which also tells us how much direct access the government has to all the AWS (and all other providers) infrastructure.
Why would encrypted data, which the provider holds no keys to, be a dangerous way For a government to hold a secret?
What if the hardware is physically located in your own country, and employees of cloud vendor are virtually "accompanied", and watched, any time they login to the hardware? That's called sovereign cloud and all cloud vendors have it.
To elaborate: robust encryption, dedicated hardware security modules (HSMs), and sophisticated key management safeguards data even if it resides on someone elses hardware.
If you design your system properly, even if the cloud provider manages the underlying hardware, your secrets remain secure because the keys and sensitive data are protected in a controlled, isolated environment.
The US Govt. seems empirically much more vested in what goes on in public restrooms than it does in what goes on in global affairs and military conflicts.
He may not have won the popular vote by much, but he certainly has a dedicated base of staunch supporters.
By their unceasing jeering, bright hats, and constant online presence I'd be surprised if there's anyone hasn't noticed them by this point.
Somehow it's worse than in 2016
* More creative threat-modeling.
* More effective prevention measures.
* More vigorous mitigation & stonewalling attempts.
* More rapid remediation & rejection of the intrusion.
Especially for a threat vector that was telegraphed so openly so far in advance. The circumstances might be unprecedented, but they're not at all surprising.
There are plenty of mitigation and stonewalling going on, but mostly through the courts.
Executives must have some power, or else the process itself becomes the executive and there's no ability to respond to anything.
If there's anybody to blame, we must place the blame on the executive wielding the power, and those who have enabled this to happen by putting that particular executive in power by subverting the traditional vetting process. If a political party no longer performs basic vetting of that level then the entire party should probably be eliminated.
He said it was what he was going to do, he was up on the stage, I heard many many people salivating for DOGE cuts like this before the election, and even today.
I agree, and frankly anyone feeling "surprised" right now probably still thinks strongly worded emails and letters are enough to solve the problems they're just now seeing. Those things rely on a stable democracy where constituents and what happens to them matter at all.
No, it’s completely different than that. Some of them I’ve talked to, they’re confused about this Musk Internet guy. And they’re confused why their news isn’t giving them the predictive edge those aware of Project 2025 seem to have in conversation. “I guess we’ll see…” “I guess we’ll have to have hope…” The same people willing to accept fabulist conspiracy theories for non-white-male candidates now openly rely on faith-based appeals about the character of the richest man in the world.
People like him don't spend without an expectation of something in return.
The more surprising thing is the amount of people who think successful capitalist = successful political leader, when the incentives and constituencies are drastically different.
> In the CNN poll, Musk having a prominent role in the administration is viewed as a “bad thing” (54-28) by a nearly 2-to-1 ratio. The Post-Ipsos poll showed Americans disapprove by a similarly wide margin (52-26) of Musk “shutting down federal government programs that he decides are unnecessary.”
> And Americans said 63 to 34 that they are concerned about Musk’s team getting access to their data, which is the subject of high-profile legal fights.
> Even 37 percent of Republican-leaning voters said they are at least “somewhat” concerned about Musk getting their data.
https://www.washingtonpost.com/politics/2025/02/20/trump-pol...
EDIT: Case in point.
If your data is well encrypted they practically don't have any access to any of the information except how much of it there is
If your unencrypted data flows through any AWS memory or compute, or if your encryption key flows through any AWS memory or compute, then AWS *can* access that data.
does this not refer to moving data?