Amazon and CIA ink cloud deal
fcw.com
fcw.com
I wonder what this means for Oracle/IBM/other on-site vendors over the next 2-3 decades.
Any other department would just say "nope that sounds unsafe and I have no idea what to look into to decide otherwise", and so ignore AWS (or basically any other modern technology) completely.
There have been lots of accounts of how badly they've botched acquisition problems, and it's all essentially run by contractors now.
I've also talked to a lot of NSA IT employees. They obviously can't divulge anything classified or even sensitive, but are always happy to get back to the commercial world.
It's entirely possible to move encrypted data into the cloud, process it, retrieve the results, then decrypt. Welcome to the future.
It'd be much easier for recruitment, to be able to advertise for developers/data-scientists/sysadmins with AWS experience, than just about _any_ alternative…
It means very little for Oracle/IBM etc. Oracle has their own virtualization solutions in Solaris support for Zones, KVM etc. (and other cloud vendors have built on that - see e.g. Joyent's "SmartOS") but might be more interested in selling application appliances that can run on these solutions. IBM would love to sell in expensive consulting services to build private clouds like these too and have a lot of experience at scale with massive systems (and have existing deployments of mainframes of theirs with 1000+ Linux VM's on a single mainframe, as well as plenty of smaller solutions, as well as hybrid setups).
And yes, we just have to hope it is not used to spy but hey, I'd take the risk in trusting that they care more about our safety than spying on us all the time.
Given the federal government's past behavior regarding domestic communication, I think it might be more prudent to behave on the assumption that they ARE spying on us all the time. They tell us that they only look at the info they've collected about us if is connected with communications with overseas persons of interest -- but that implies that they will have already collected it. It's the only convenient way to have a well-populated history of activity for $Person.
Don't confuse cloud and open. They refuse to even acknowledge it publicly, this is just another vendor contract for storage and compute resources.
While security is of great importance, it has more to do with the trust in your business relationship than where bits are stored at the end of the day.
I'm sure that a contract worth $600 million over 10 years would change one's tune.
The depressing thing, as a taxpayer, is that this AWS contract is probably just a fun $60M/year toy for TLA's to play around with.
It makes sense - government needs to host their files somehow, as we are moving into this digital age.
I don't see anything wrong with it, though it will further cement Amazon's standing as a big business superpower.
1. url
1: https://news.ycombinator.com/item?id=606843 2: http://arcfn.com/doc/app.html#markdown
This, however, shows that they are using AWS (EC2) for hosting:
$ host -t a barackobama.com
barackobama.com has address 50.19.226.77
$ host 50.19.226.77
77.226.19.50.in-addr.arpa domain name pointer ec2-50-19-226-77.compute-1.amazonaws.com.For example: http://www.carpathiahosting.com/carpathia-hosting-announces-...
I came in here expecting firm proof that the CIA was using Amazon to spy on my Prime subscription.
(I guess I assume they can do that anyway.)
But where's my free outrage?
Kidding aside, doesn't this seem like exactly the sort of move you would want your government agencies to make? Take advantage of free-market services where appropriate, and not get all "NIH"?
What do you mean by this? I did not get this reference.
Furthermore, while I'm acting mostly on assumption here, I doubt the agency is going to Amazon because they can't build and/or afford their own setup.
I can build and I can afford my own versions of a great many things. I still buy from vendors.
Anyway, AWS is heavily segregated. Simply having consumer instances is not going to enable them to snoop your traffic, and simply having consumer instances is not going to enable them to make Amazon give them your traffic if they couldn't make Amazon give it to them before.
So not exactly NIH unless your claiming that Tommy Flowers etal at the Post Office and Bletchly park invented this
"I came in here expecting firm proof that the CIA was using Amazon to spy on my Prime subscription."
While that's no doubt already happening, it's also abundantly obvious that Amazon is one of very few organisations that anyone, CIA or not, would go to for consulting/professional-services when setting up a large-scale in-house "cloud computing" infrastructure.
There's not a large pool of companies with demonstrated experience, apart from Amazon there's maybe Google, Facebook, Microsoft, Rackspace - I wouldn't add Apple to that list (since their "cloud" track record is pretty poor), from there you end up with vendor-lockin from options like IBM, Dell, and perhaps to a lesser extent Cisco.
Out of all of those options, Amazon seem to easily be the "best choice" if I were to be setting up a decade-long partnership to deploy a multi-data-center scale private cloud.
Also love how the GAO's IT director is named Dave Powner.
Sure, they also do good / important work. And it's hard to say if they're still as bad as they used to be, as it'll take decades before the most important details about what they're doing now gets declassified. But their history doesn't exactly give a lot of confidence.
I am sure that CIA and SIS officers must get annoyed some times as how the FBI and SS (MI5) are normally the heroes and the CIA /SIS are the bad guys.
If anything, this tells me that the CIA didn't actually have enough computing power and/or competency before to do it on their own.