Of course this rules out all 'cloud' software other than simple dumb data storage. RMS was right again[1].
[1] "Cloud computing is a trap, warns GNU founder Richard Stallman" http://www.theguardian.com/technology/2008/sep/29/cloud.comp...
Of course this rules out all 'cloud' software other than simple dumb data storage. RMS was right again[1].
[1] "Cloud computing is a trap, warns GNU founder Richard Stallman" http://www.theguardian.com/technology/2008/sep/29/cloud.comp...
Mostly the same reason they rely on third party infrastructure like electricity and plumbing: economics.
Cloud services has none of that, and can cut off service for any reason. Work on any competing services that "the company" dislike, or do anything disruptive to people in power, and instant see your future, your business, you speech be taken down to a 404 not found. Any logs, any files, any property at all confiscated. Even pure money is not safe from "indefinite suspension of the account".
Maybe this is a lesson that if you ever want to legally produce a scam, steal, or do anything that normally would land you in jail, all you need to do is go into producing third-party digital infrastructure. There is basically nothing a cloud service can do that would lend the owners to go to jail except tax evasion.
http://aws.amazon.com/compliance/
https://aws.amazon.com/security/
http://aws.amazon.com/govcloud-us/security/
http://aws.amazon.com/agreement/
There was not a time when the mass population had their own generators, then flocked to supplied electricity in preference. They never had power independence.
Water was originally done locally, rivers and what not, but hygiene and health became a game changer. The benefits were huge and clear.
The whole history of all three are so different, you cant reasonably compare any of them.
In-house computing infrastructure is very expensive and most firms have their comparative advantage in doing Something Else, so it makes much more economic sense to run on AWS or somesuch instead of buying a pile of physical machines and running their own server farm. Likewise, many web and mobile services provide huge benefits for their users via network effects. I personally don't enjoy using Facebook enough to maintain an active account, but many millions of people clearly do, and I can't say they're wrong for choosing to spend their time that way.
What hosting solution(s) your own company use?
We use Google Apps, Trello, Wave (for accounting), Corona SDK (that builds in Corona cloud servers), Google Drive (previously was Dropbox), Google Docs (we never used any office here, MS, Libre, or anything else), and so on...
I am personally against it, but the CEO decided it that way because he did not wanted to bother about IT infrastructure, we are not big enough yet to bother about it, cloud stuff make things much easier.
BTW, IT infrastructure? You are all networked, right? So, whats left? One large ish server? Hardly my idea of "infrastructure", which to me implies something a bit more large and diverse. IMHO, being networked for the internet means you already have infrastructure, ish!!!
We don't even have a place to put a server... We already freak out enough fearing people will steal the workstations and test devices! (we are in Brazil, last year there was 20 mass robberies, 90 cops executed, several random murders, and 3 different incidents resulted into homeowners ending in hospital after being shot with military-grade rifles in common robberies)
My last employer was not into 'the cloud'. Just a smart manufacturing company, with sites in five countries, two data centers, one on each continent.
Which would die in about a day without the internet.
Each site could chug along for a while, but without the bits flowing in, and out, coordination gets out of whack and after about three workshifts they'd have no idea what to work on next.
Cloud or not, if the internet goes so goes the business.
That or they'd ask us to re-install those doggone fax servers we retired in 2007.
In any case, if your servers are running but you can't connect to your suppliers and customers - you might as well turn them off, your business likely can't function without connectivity even if you avoid the cloud completely; so avoiding cloud doesn't decrease your risks much.
Just buy two or more redundant, reasonably different internet channels - and then prolonged loss of connection is no more common as other major downtime risks such as flooding, fires, etc.
(I say this from a position somewhere in-between: I was born in British Columbia, and my birth date is right on my birth certificate, but wrong on the public-health-plan card you also get issued at birth. I had a very strange time bootstrapping my first credit card...)
I also have my adoption papers, and I left the country I was born in when I was young (7 years). As far as the country I live in is concerned I'm my Father's last name, but have legitimate primary ID with my mother's pre marriage last name.
Always wanted to get my spy on and build up a second identity with that. Of course that's highly illegal, so itw only ever been a fun thought exercise :)
Remember that video that was posted of a Lawyer given a talk to law students about never speaking to policemen? Remember how innocent things can be completely twisted and used against you?
Yeah, I'd worry about the NSA snooping in my calendar.
Unless the government puts explicit restrictions (not secret restrictions!) on how their resources (not just stored data!) can be used and actively punishes those using it improperly, then it should be assumed that all the resources at the NSA's disposal will be used for the convenience of the rest of the government.
sharing your calendar can be twisted against you.
not sharing your calendar can also be twisted against you ("you don't seem to be sharing your calendar like most of your fellow citizens, what are you hiding?")
see: mccarthyism.
Perhaps we should exercise our little grey cells more. Granted for a busy sales man or something that's impractical, but Im sure we could generally commit more exclusively to memory..
I posted this before, but to repeat... I think the legacy here is that we move more and more as a matter of habit or routine to a more secure way of living. No, we cant ever fully insulate ourselves from the NSA, but I think more and more of us will commit less to the internet, choose HTTPS via automatic extensions, use more secure software as a default, self censor, and so on.
And how will they be treated? It seems: poorly.
FWIW, I'm not even from or in the US of A, but I'm worried about my government doing something exactly like that considering how much it's cooperated with the NSA directly in the past and present.
BTW it's a major trope in spy movies. Literally dentist appointment in "The Tall Blond Man with One Black Shoe" ("Le Grand Blond avec une chaussure noire").
It is possible to make cloud services where trust is not needed. It remains to be seen if cloud services will have to change to remain in business.
When my laptop had water spilled on it, there was no need to worry about my thesis. I went to a lab and started working on it again 10 minutes later. No work lost. My own backup solutions would be far worse, and likley involve losing some work.
When using these services, I have to ask myself, how much do I value my privacy? I think I get more from google's services than I lose. For me, and a lot of people, it's not worth the time to set up an email server, let alone maintain one.
I'm not trying to change your mind; not everyone is meant to run their own systems. But I certainly want to counter your discouragement against doing so.
But then where do you get the software for said server? Or your mobile client? We're back to the age old question of how do you trust the compiler? How do you trust the source code?
There's a reason that Governments that take security seriously have their own, private, WAN infrastructure that has gateway upon gateway before it reaches the internet, if it ever does.
Heck. I really could host everything at home but the mere thought of the periodic hassle when some hardware or software inevitably breaks... I'd rather simply send all my email archive to NSA, KGB and Chinese gov't, the hassle is really not worth it (for me).
This is pretty much the conclusion that I've come to as well. Using cloud storage to keep thing in sync, but only doing decryption on the client. Even doing something like storing a SQLite database and encrypting all of the fields seems like it would be leaking information rather than just encrypting/syncing the entire database.
http://www.theregister.co.uk/2013/09/10/boffins_propose_more...