Be cautious about using Chartio (or at least, don’t follow their directions)
codingkilledthecat.wordpress.com
codingkilledthecat.wordpress.com
In anything that is cloud based there is going to be some level where some hacker could get in and destroy everything. Most people on this site use cloud hosted servers, all of which would be at risk if Amazon or Rackspace got hacked. BI in the cloud is a new space and will be cautiously entered by some, but benefits will outweigh the potential risks and just as has happened in every other segment of cloud computing.
(will write more soon)
With regards to cloud - you're right, Amazon and Rackspace and so on are a single point of failure for a lot of businesses... but they also have a lot of people dedicated specifically to keeping their systems secure. The average startup, on the other hand, doesn't.
Those guys for sure have a lot more manpower than we do (so far!) but I might also point out that security isn't totally about how many people you have working on a problem, but how simple you're able to make it. But - that's not me getting into a security argument...
It's debatable whether DWH is more or less secure than your approach - and it also depends heavily on how the DWH is done. Having to explicitly move data around also gives an opportunity to scrub it.
For the record, the proactive approach you're taking with your responses here is heartening. The goal of my posts is always, in the end, to push for something better, not just tear down what's there. Glad to see that you've an open mind towards improvements.
We've spent a lot of time thinking about security risks and writing code to reduce them. I thought I'd share a few things we do and that we've learned from our experience:
* The agent approach is the most popular because it allows for a system administrator to easily sever the connection from the database server without having to worry about writing queries to revoke user access.
* We never run unindexed queries without an explicit request from a customer and a manual entry from an Emergent One employee.
* We're currently looking into security consultants to continuously test our production environment.
* We're building an appliance version of our software much like Github Enterprise in order to accommodate the customers that aren't comfortable with their data hitting the cloud.
* We strive to have very quick and personal customer service directly from engineers. The vast majority of the responses are within the hour.
and last but certainly not least...
* The very best thing we can do is be honest and straightforward about the inherent risk behind our platform. Being able to build and maintain a pristine level of trust is the only thing that will keep us in business.
I'm sure Chartio does things very similarly. Direct-database access technology is not for everyone, but it's also proving to be extremely valuable for both Chartio's customers and ours. The cloud advantage that makes most SaaS software great is still there.
One thing we try to do is be open about all this and we explicitly mention it in our docs[1]. This includes instructing users to explicitly limit the permissions that they grant.
Another poster mentions loading a pre built VM. thats actually our goal for the enterprise as there will always be systems are not (and should not!) be accessible to the open Internet. In the meantime though there plenty of folks happy with the convenience of living in the cloud.
Also, the oozing, patronizing tone of the author is really annoying. Just make your points and be nice about it.
* make a new schema called chartio_only
* add a chartio database user that can only access that schema
* add views to the chartio_only schema
Now chartio can only access the views in the chartio_only schema.
Take Splunk, a $4 billion dollar (in market cap) machine log analytics service. They rolled out a new service called DB connect which allows you to integrate database analytics with their platform. Their implementation of DB connect is equally intrusive. However, I can still see these services being useful for visualizing operations that are less critical.
I'm more concerned about the more enterprise-y products aggressively advertising 'enterprise' security features like Active Directory integration, smoothing over their total lack of transparency in vulnerabilities and bugs.
1. gives a copy of your data to someone else 2. is legally questionably still your data 3. is stagnant (as you usually only backup once a week) 4. there is no way to track where that data goes
Each involve giving away some type of control.
Also your support system is annoying: why do we need to register for support if we're already registered on your site? And having to have a password with uppercase and symbol is overkill for a support system (and is pointless anyway, as you'll probably have to write the password down).
This is the exact definition of a "crunchy center", and I wouldn't be surprised if they do other horrible things. You know for certain there are no passphrases on those SSH keys either.