Amazon WorkSpaces
aws.amazon.com
aws.amazon.com
Can't be used in G. for the same reasons MS Office 365 is off limits, sensitive personal and business data don't belong in non german-hosted clouds.
One part of me wants that easy carefree cloud life, the other part doesn't want to feed the US-overlord anymore with our precious informations.
The price differential between buying the hw/sw & staffing a professional (or team of professionals) to curate and maintain it 24/7/365, or simply off-loading it all to an outside party, could be huge -- I'd dare say huge enough to make or break a company. From an executive POV, why care about data safety, when hosting it yourself makes your business model non-viable?
I realize there are lots of problems with this line of thinking, and I'm not advocating it at all, but I'm willing to bet this has been the case for some.
Building a government you can trust will take several generations, with each generation providing hundreds of thousands ENTIRE LIVES to the cause. It might be efficient in the grand scheme of things, but from an individual or even corporative point of view, it's terribly inefficient in any timeframe you might consider.
They use custom Apple/Mac software for all their POS equipment. You know how many people run an IT department that is charge of that much equipment, people, inventory and software?
TWO.
Scale that up to five thousand seats. Five thousand seats is big? Not really.
Every day a piece of hardware dies. Every month someone rolls out a new software package. There are many different user profiles, accounting, sales, warehouse, IT, marketing, executive. Then there's that one guy that needs that program that only runs on XP SP1....
Every IT department has to justify its cost per user. Once you get above 1K seats, a lot of things that seem like overkill start to make sense really quickly.
All Amazon is offering is a managed version of what larger companies have been doing internally for years. Just like their server business, it seems expensive until you actually work out how much it would cost to do it yourself.
Because they offer better security than I can build in to my own home (at least not without significant effort) and they offer guarantees should my money go missing under many (but not all) circumstances (for example, the savings guarantee if a UK bank goes bust).
Do cloud providers offer the same? The guarantees may vary dependent upon service contracts (uptime, backups etc), but the idea that their data-centre was better secured than my company server-room was supposedly a given (at least for most small to medium organisations).
EDIT: added qualification to last sentence
The insurance is just an incentive to keep my stuff safe (and in the case of savings guarantees, an incentive to keep consumer-facing banks from going bust).
If you have a secret, why would you even store on the Internet? If you are worrying about conversations with your friends, that kind of privacy, don't log it. If you can't trust Google/Skype, you have to find your own solution.
For me, I got a lot of cat photos and I don't know what NSA could do with my cat photos.
There is also a Safe Harbor scheme that is intended to overcome this problem so working with US businesses is still possible if they provide additional safeguards. However, it's now clear that no business operating in the United States can actually offer the required guarantees, no matter how sincerely they might wish to. It is therefore unclear whether a European business relying on Safe Harbor to cover its rear would actually have much of a case in court if one of its customers were actually damaged as a result.
I've seen a lot of businesses at least considering pulling out of US services, cloud or otherwise, for this reason in recent months. Some are sticking with it, on the grounds that there is safety in numbers: no government regulator really wants to damage global trade by making examples of businesses who are just trying to do their work and acting in good faith, and if you're dealing with a similarly honest business from the US then the odds of an actual customer complaint are probably low enough that it might be considered an acceptable business risk. Others seem to have lawyers who are more wary and fear the penalties of something like a mass leak across the pond that would come back to bite their clients back home.
In addition, some nations in Europe are a lot more concerned about privacy both legally and culturally than the US, for obvious historical reasons if nothing else, and they may have stronger laws still.
Can you provide more data on that?
I'm 'only' a system administrator, but I'm working for a company that is doing business in the both US and UK.
Real Soon now we're going to be standing up a stack in the UK .. but I'd like to know what safeguards I can't guarantee so when I'm dealing with _two_ data sets and _two_ code bases and squared complexity I know _why_.
It will help at 3 a.m.
I don't know anything special that hasn't been all over the news anyway.
Basically, the US government seems to be actively trying to compromise data held by US businesses on non-US citizens. That same US government has made it clear in public statements from the highest levels that they don't consider foreigners to have any privacy rights at all that should prevent this.
Given that this all happens in secret, any promise made by any business operating in the US that they will safeguard personal data of non-US citizens to the standards required by European law is now known to be worthless, even if it was made with complete sincerity.
This is now common knowledge, and anyone controlling personal data in Europe would have to take it into consideration when applying the general data protection principles. In other words, any legal cover afforded by the Safe Harbor scheme may not be worth anything any more. (In case your question was intended to be about the Safe Harbor programme itself: This was created so that US businesses can be used to process personal data from Europe, as long as the US business promises to uphold similar data protection standards to those required by law of European businesses.)
So the bottom line is that as a European business, if you don't have adequate disclosure when you collect any personal information that basically says it might be exported to somewhere without any safeguards on how it's used, and you don't get prior informed consent from everyone whose personal data you are dealing with, you might be on the hook legally for regulatory non-compliance as well as for any actual damages that result from any breach. Whether it's possible to give prior informed consent to a carte blanche handling of the data is itself debatable.
(Just to be clear, my comments in this thread are based on the perception of the current situation as I have encountered it anecdotally in a few cases. Some of the people I've spoken with may have taken legal advice, but what I've described here is not based on formal legal advice I or any of my own companies have received. Please consider these notes as food for thought only and for goodness' sake don't rely on them instead of taking proper advice if these kinds of issues might actually affect you.)
Understood.
Also, thank you very much.
It's hard to know exactly what the US law is too because it's classified. I would not trust that any country is safe from snooping--always assume it will happen.
That was what led the initial opposition to the Patriot Act, FISA Amendments, etc. was that they would make NSA programs like the ones that have hit the news substantially (if not completely) legal. That's apparently not what Sensenbrenner had intended when he drafted Patriot Act, but it was exactly this kind of issue that was raised at the time by privacy groups and promptly ignored by policymakers.
US law is very tied to court precedents, so a secret court with secret precedents is "secret law".
http://www.nytimes.com/2013/07/07/us/in-secret-court-vastly-...
> In more than a dozen classified rulings, the nation’s surveillance court has created a secret body of law giving the National Security Agency the power to amass vast collections of data on Americans while pursuing not only terrorism suspects, but also people possibly involved in nuclear proliferation, espionage and cyberattacks, officials say.
> But since major changes in legislation and greater judicial oversight of intelligence operations were instituted six years ago, it has quietly become almost a parallel Supreme Court
> “We’ve seen a growing body of law from the court,” a former intelligence official said. “What you have is a common law that develops where the court is issuing orders involving particular types of surveillance, particular types of targets.”
Etc etc.
The safe and conservative option is to assume that the executive is doing literally anything permitted by the public law without the aid of 'activist judges' (as the GOP would say) on your side of the argument. This is exactly why it is so important to be judicious in crafting legislation, as the judges will operate by what's in the written law not contrary to the Constitution when the law is clear. They only start worrying about "what the legislators meant" when the law is fuzzy.
That's also why it is important to quickly get a legal framework around foreign surveillance that includes recognition of the fact that the Internet is global while the Fourth Amendment is domestic. MUSCULAR is a pretty shocking breach of what we all understand the Fourth Amendment to mean, but I guarantee that it's technically legal. It shouldn't be, but the Fourth Amendment has long been known to effectively not apply at all outside of CONUS.
EDIT: well, I guess I'm sorta wrong. The whole thing looks complicated. Making sure you don't violate German data protection laws is confusing [0][1].
[0] http://www.thomashelbing.com/en/analysis-data-protection-aut...
[1] http://blogs.computerworlduk.com/cloud-vision/2012/04/cloud-...
The Safe Harbour program is a weak attempt at saving face: as long as the Patriot Act exists, no US-based company will ever be able to comply with EU privacy laws as they stand. Being "compliant with Safe Harbour provisions" only means that they're making promises they won't be able to keep.
Legally it's not allowed, but you have to have ten lawyers backing you to make people in your company believe you that Office 365 and other SAAS Software isn't legally usable... Google Apps for Business, ZenDesk... We've just faced this situation with a customer who we've shown several lawyer inquiries we've sent about this topic and he flatout replied: "Well i guess your lawyers aren't very good then."
Those guys pitched at the Pioneers Festival in Vienna two weeks ago, and there's really something to the idea of a private, plug- and play box in your office which hosts something like a cloud. They are from Germany, too. It's too expensive for our uses, though.
So actually just another us-too product from big corp. Next Google news in 3, 2, 1....
I am looking forward to see more of those initiatives. This growing distance between one and ones data is a dangerous path anyways, see also the rise of appliances and the decline of full access pc. it takes responsibilty away and media competence.
This is almost certainly the most efficient and optimal way to do desktop computing. We've been waiting really for decades for networks and CPUs to get good enough that it's actually viable for a real good experience on the client end. And when we finally get there, the NSA and others are here pissing all over the party.
I hope that some day there is a full accounting of the enormous economic damage caused by the reckless, dangerous people in charge of these organizations.
I honestly doubt 99% of consumers care, since the NSA isn't concerned with their business.
That's not to say that attitude is right or wrong, but it's probably the last thing on most peoples' minds.
The NSA is hardly the only organization/party who could exploit a service like this. Every local police force could get a warrant to search your personal computer data without you ever knowing.
I recently attended a talk on wiretaps by a lawyer recently, and when there is an investigation going on, police used to tap 1-2 cellphones a few years ago. Now 50+ people at a time are brought up on a warrant. Including a lot of people who aren't related to the crime (for ex. the targets mother).
So who is the "1%" of that 99%? Who should care about their privacy? How do consumers know they aren't in that 1%? The answer is they can't and they don't know.
But ultimately, they just don't care. Until it:
A) affects them personally (or to someone they know),
B) someone explains why it matters (if they have a technical knowledge gap)
C) widely publicized examples of abuses become part of mainstream news
Those three combined could eventually become widespread enough to destroy services like this. But right now, yes, the risk is still minimal in terms of public perception.
They can also get a warrant and come to your house and go through all of your stuff (including your personal computer) there. Of course you'd know, but not until it happened. There's no real "protection" from a legal search warrant.
The privacy implications and constitutional externalities are much larger (and easily abused) when it involves the interception of voice calls, emails, sms, locations, etc and now potentially all computer activity that happens in memory.
Wiretaps involve analyzing past data and actively monitoring new communications. Including every person you call or every website you visit. Police often have to delete 99%+ of intercepted data because it's irrelevant to the case.
That's different in many ways from a single physical search warrant on a house or computer.
And now they are becoming the go-to investigative tool for every criminal case...
Using your analogy, the 99% of things the police are supposed to ignore, such as their clothing drawers, does not carry equal weight in terms of privacy.
I'm not unique in having this position, lawyers/judges/courts view it as a much broader breach of privacy as well and they (often) require much stronger legal restrictions for the police than a standard search warrant.
Third party requests for data are different, these often only require court orders or subpeonas, which don't receive nearly as much scrutiny. Your information may be accessed by an investigation relating to another person, for instance.
Your best privacy protection is to store stuff at home and access it remotely using an encrypted link, and to store your credential securely. (Think smartcard.)
But the decision to purchase this will be made by businesses. Are you equally confident 99% of businesses won't care about literally 100% of their corporate information sitting with Amazon, which in the past has shown its willingness to subject international customers to US pressures?
https://www.eff.org/deeplinks/2010/12/amazon-and-wikileaks-f...
The growth of cloud (storing all your important shit on hard drives owned and operated by someone else) has been increasing these past few years.
I thought the world had gone batshit insane even before the NSA leaks, but it appears I was part of an incredibly small minority. Some people may have come to our side, but not many. Because really, if you don't care that Company Y has access to your shit, what difference does another third-party make?
People that think like me are definitely the minority, unfortunately.
True, but some of the rest (like me) are more concerned with Amazon (or Google, or Facebook, or Apple) having access to their information than with the NSA. Personally, I'd rather have a government spying on me than a corporation.
In fact, most of the traditional large enterprises in the US keep teams of people around to operate policy and software solutions solely to archive and protect data that may apply to government and civil investigations.
Large enterprises are concerned about individual actors - "hackers", competitors, unscrupulous investors who want to gain access to sensitive information. If the government comes calling, they'll just give up the information, because why do they care? The vast majority of large companies in the US don't store sensitive information on behalf of their users like Google does. If Exxon-Mobil can save $30m/year by running VDI on Amazon, they will - if the government wanted the contents of any employee laptop, they'd turn it over anyway.
It's end-users, service providers, and politically active organizations who don't want to put their compute on centralized infrastructure.
Yes, but it's not about you. It's about your company, the legal obligations they have to protect your data, their customers data, and their internal IP from outside intervention.
Consider that you have a legal obligation to protect the privacy of your data. Now if you are served a warrant to give up the data or to secretly tap connections to your server, you are probably legally covered. But when they just go straight to Amazon to get your data you have no such cover. Users can rightly ask why you put their data in a place out of your own control, your own legal accountability.
Prior to this year, one would have said that such events were so extremely rare, and in such exceptional circumstances (on credible threat of an immediate major terrorist attack, etc) that it was an acceptable risk for a business to take. That's now flipped. The presumption is that if you store data in the cloud then it is being routinely intercepted and is freely available to a multitude of parties outside of your control. That's the crucial change that is going to put cloud storage and services off the table for anyone with sensitive data.
Until the industrial espionage and insider trading leaks come out. Then all hell will break loose.
Or they will still not care.
If that's something that affects 0.001% of business, and if some culprits have been found and punished (for the leaks to come out), then businesses will probably continue using AWS and not caring, thinking "what are the chances"?
Except if something causes direct and measurable money loss, they wont really care, even if it's proven to have hurt this or that other company.
I very much doubt 95% of the potential audience will even care about that.
>This is almost certainly the most efficient and optimal way to do desktop computing
I fail to see how it's the "most efficient" and "optimal". I don't see anything optimal about struggling with network level latencies in some remote shared system.
>We've been waiting really for decades for networks and CPUs to get good enough that it's actually viable for a real good experience on the client end. And when we finally get there
For tons of applications we'll never "get there" (compared to client computer). The latency, even the one caused by the speed of light limit (200 ms for a roundtrip around earth), is big enough to be disturbing for a lot of desktopy stuff -- much more if you add all the additional latencies and factor in common connection speeds.
http://www.theguardian.com/world/2013/sep/09/nsa-spying-braz... http://www.dw.de/germany-fears-nsa-stole-industrial-secrets/... http://www.globalresearch.ca/nsa-busted-conducting-industria...
Thank you.
As I see things, the only possible way that the NSA's misuse of their powers (specifically regarding non-US persons) is likely to get curbed is when companies realise there's significant revenue implications. I have _zero_ voice in US intelligence gathering policy. I _do_ though, have the ear of people buying services from US companies who _do_ have a voice in forming/changing those policies. Google's position at the top of the web search food chain, and the amazing advertising business they've built on top of it, might not be enough to justify the risks involved in exposing all that data to the NSA. Microsoft/Yahoo/Google's enourmous slice of the webmail market is also a dubious value proposition if you evaluate the risks in a certain light. Amazon's dominance of the "cloud" market isn't unassailable if you take legal jurisdiction and corporate ownership into account. Salesforce becomes suspect as well for non-US users (both as a CRM and their entire force.com platform).
Those are my most likely allies in lobbying for non-US-citizen's basic human rights online. If Google, Microsoft, Apple, Yahoo, Amazon, PayPal/eBay, Facebook et al. don't start telling your government that they're losing significant revenue because of the behaviour of US intelligence gathering services, then "outsiders" like me are inevitably going to have to find alternative jurisdiction to buy those services (and to create/use replacement services with robust modern anti-nation-state-snooping levels of crypto baked in from the start. Who wants to bet against Silent Circle's Darkmail becoming a serious SMTP replacement because the Brazilian or Equadorian or German or Chinese government mandates it's use nationally - even if it's only done as a political point-scoring "stunt", something like that could be a _major_ win for global internet privacy.)
As others have pointed out, the NSA can spy at will everywhere else in the world. Nevermind that Germanies spies are probably in on the scheme.
The risk from private bad actors on the internet is much higher.
Even if I agreed that it was appropriate/acceptable for trusted NSA staff to have access to all global email/phonecalls/whatever - it's _obvious_ they don't have adequate protection in place to prevent mis-use. When they've got cutesy nicknames like "LOVEINT" for things that are obviously so common, yet are (or should be) criminal abuse of positions/power – how could anyone accept "the NSA dragnet"?
I understand "national security" is important. I understand "stopping terrorists" is needed.
I also think if the US government, people, and businesses think "the rest of the world" will just sadly watch on as they allow the NSA to continue doing what they are doing, they are mistaken - and the blowback will be _astoundingly_ counter-productive for the NSA's _important_ goals. When it becomes clear that we need (and can create) things like strong crypto with easily useable software, TOR-like anonymising techniques (but not, of course, your US government designed and probably exploited TOR), encryption where we trust both the math and the implementation (and by "trust" I mean trust mathematicians and software crypto experts from non-US backgrounds, and preferably from conflicting backgrounds as well - I'd take software/crypto advice agreed to by a majority of Russian & Indian & Brazilian & Equadorian & Chinese experts over conficting advice from Schnier or Zimmermann or and US or Five Eyes affiliated person/business) – we will. And when "the next level" of "secure against the NSA" communication tools become available and widespread - and widely made available to politicians, businesses, journalists, and regular citizens - guess who _else_ will have it? And how will the NSA conduct their "war on terror" then? (and their less acknowledged but very real "war on drugs" and "war on non-US companies profits" and "war on journalists critical of US policy" and "war on US citizens demanding their government be held accountable"?)
I appreciate the response, as I feel like many people post here with sort of an implicit perspective that it is obvious that pervasive NSA spying is a catastrophe.
I still maintain that all of the issues you've outlined are not going to considered that bad by your average citizen. Especially in comparison to the pain and cost of duplicating Google's type of services on a personal or organizational level.
So what is interesting to me is that, if you grant my premise that your average civilian is not going to be that upset by this, so many tech types have such an opposite response.
While it may be more doable for a techy to set up secure web services, it still strikes me as an outlandish use of resources given that the vast majority of them truly don't have anything to fear from the NSA.
Figures like Snowden are a special case, as are anti authoritarian crypto activists, as the intelligence community obviously sees them as a threat.
My thinking generally is that there is no way to stop the NSA and similar agencies from spying like crazy. So if we all just assume that all of our electronic communications are non private, it simplifies the issue. (Considering the internet as public space). So to have secure computing, you simply can't hook your computer to the internet.
What is more disturbing to me than the spying is the ridiculous over use of secrecy and classification, which I think breeds far more opportunities for abuse. For pulling the curtain back on this, Snowden is a hero.
Is there any evidence that this is the case?
The one you linked is about AppStream
It currently says:
Performance - 1 vCPU, 3.75 GiB of memory, and 100 GB of persistent user storage.
I believe it should be:
Performance - 2 vCPU, 7.5 GiB of memory, and 100 GB of persistent user storage.
A very interesting move by Amazon. Wish it was available by the hour, though.
My second thought is the price point is to high but obviously that will come down (However by having a high price point you will invite competition.)
I'd like to use this just to be able to use the vsphere app which runs only under windows. So from a mac I have to connect to a windows box by screen sharing. I could use this. But the $35 price point is way to high for doing that.
Amazon doesn't have a history of entering the market at a high price point. It might be high for your use case, but your use case isn't what they're after. VDI is a desktop replacement where you run all your applications, not just one or two on an as-needed basis.
> Your users can access the applications, documents, and intranet resources that they need to __get their done__, all from the comfort of their desktop computer, laptop, iPad, or Android tablet.
Otherwise, thank you for the detailed write up... I almost never watch launch/demo videos
"All WorkSpaces Bundles provide the Windows 7 Experience to users (provided by Windows Server 2008 R2) ..."
I'm curious. What are the font-rendering differences? Are you sure it isn't caused by Remote Desktop or by the difference between software and hardware rendering?
I think their timing is quite bad. I doubt many non-us companies will start to move a big part of their infrastructure to the cloud of a US company right now.
On the other hand for smaller businesses that don't have to fear espionage this could be a really cheap way to lower costs.
I've been managing full 2,000 virtual desktops and about 100 servers... I've been looking for a way out! (out of licen$ing/$oul agreement with MS and VMWare).
Of course latency would be an issue, I wonder what solutions they have for low/limited-capacity clients.
http://aws.amazon.com/workspaces/pricing/
Talk about high TCO! (yes, you still need the hardware to run this service). With office going online now, I'm wondering what their strategy is. This is really not what I was expecting.
Not saying it still wouldn't work out cheaper for you, but worth bearing in mind.
http://aws.amazon.com/directconnect/
I would imagine it's at least in the ball park if you have 100 servers..
What is this? A virtual desktop service for time travellers?
They could have installed IE10 or IE11 -- which are good. I can't think of a good reason for installing IE9, though maybe someone will come up with one...
IE10 snuck onto a few servers and unrestricted desktops because it was installed silently through Windows Update along with the normal patches. That did give us the unexpected opportunity to test it out with real users.
Presumably it's upgradeable...
Then, after that happens, they have to retrain everyone on the changes.
How am I saving on licensing cost then? If I can install the client on a Linux machine, it makes sense. If I need an Apple or a Windows machine I'm ... double licensing?
If you have 1000 workers using software locally, you need 1000 licenses.
If you have 1000 workers using software in the cloud, but only 100 at any time, you only need 100 licenses.
Kindle XL HD Flamethrower Lappytop.
[1] http://aws.typepad.com/aws/2013/11/tco-comparison-amazon-wor...
There's still a client PC cost...
There are also the times when either Amazon (or Google Apps & Docs) or the network goes down and you have the odd thousand people sitting around wondering what to do. That's always lots of fun.
I can see more companies providing funds to employees to buy the device they prefer instead of provisioning a machine for each employee (ours does that already). Then the computer can be used locally for personal needs and through the virtual desktop for work.
Though as I've been traveling more lately, I can see how the need for a persistent, high-quality internet connection can be an issue in the field.
Plus if I already need a computer running OS X or Windows then why would I want to pay again for renting a Windows license (As in, the monthly cost will include the cost of the Windows license)? How would the specs of the Amazon WorkSpace compare to the existing Windows or Mac Desktop PC? It might be more useful if I could use a thin client running some barebones Linux distro to access the remote workspace.
I don't work with a company that has a large IT deployment anymore but when I did their processes was not that different. They had a single image that was on every single PC and contained "standard" software. If there was any kind of problem with the machine, they'd just reimage it remotely (PXE) and if it still had problems they'd just send the machine back to Dell and get a replacement.
Although management/maintenance was not really my point. Rather, if you already have functional working machines with Windows / OS X (or have to purchase them) then Amazon WorkSpaces seems expensive. If it was accessible via some cheap thin client that did not require a separate client OS license (+ the hardware that comes with machines ables to run Windows / OS X) then it would seem more appropriate.
As I understand it, some of the motivators are:
1) The image is immutable (by normal users). Each startup is clean, so the potential to screw up your install is very low. Only user folders (redirected to network storage via GPO) persist.
2) You can indeed use thin clients, i.e. http://www.neweggbusiness.com/Product/Product.aspx?gclid=CIT... with VDI. You can also use old/underpowered/very cheap PCs.
3) Unlike an RDP setup, each user has their own OS instance so you don't have concurrency issues.
4) Windows Server and User/Device CALs are indeed very expensive. However, license costs for the clients are not even slightly relevant because mainstream desktop/laptop hardware comes with mandatory OEM licensing anyway and large businesses are not typically building their own PCs.
I'm currently working with a client in Singapore that requires that I connect to their data center through a B2B L2L IPSec tunnel that is sourced in California. So, From Singapore, I connect to the VPN concentrator in California, and then from there, connect to the clients site in Singapore.
So, every keystroke that goes to a server approximately 100 meters from me, Starts off in Singapore, crosses the ocean to California, comes back to Singapore, returns back to California, Comes back to Singapore again.
I do this for about 8-10 hours a day - completely workable.
Oh, and the Connection to the internet that my VPN connection rides on is a 3G modem, no less.
I think the best practise is to automate. Waiting on individual key presses to be echoed back when there is latency is incredibly frustrating, a slight delay while a shell script runs is completely unnoticeable.
I once used it to download a Steam game and tunnel it through a non-quota-counting path back to my computer.
This was around 2007-2008 or so, so it's tough to find anything that still remains from the project -- we sucked at marketing and didn't really get a userbase, so it died off.
Here's a few docs from it that still remain online: http://www.cis.temple.edu/~wolfgang/c4339s08/WebDesc/
"As an extension of its ongoing collaboration with Amazon, Citrix is now delivering its innovative networking and desktop virtualization solutions from AWS."
I don't see a developer finding this useful at all.
I wonder what it does to business internet prices too.
You can SSH into your Linux desktop to do programming and heavy computing, and use web apps.
If you need some GUI, you do a web app on your server and connect to it from the browser on your Chromebook. (Instead of a full-on remote desktop VNC.)
This is a really nice way to work. And your Chromebook is disposable/wipe-able. It's basically a terminal. Welcome to 1970, but with the web app twist.
And of course you can SSH/browse into that same server from whatever else, too. Like a tablet, a full laptop, or even a desktop.
A lot of our initial hardware costs have to deal with planning for spikes in usage. At any given time we may only see 10% use -- but come the end of the semester -- that could very well jump to 10x our average load. And we have to have the hardware allocated for that. It's a balancing act between how much we can expect and how much we can feasibly budget.
I can see this being a huge win for education. We have a department that oversees all IT related tasks. They also chip in occasionally to help establish foundations for best practices and unite all the community colleges on single platforms (email, learning management software, internet services, etc.). This might be right up their alley.
"In July 2013, reports circulated that Oracle was ending the development of Sun Ray, and related products.[4] Scott McNealy (long-time CEO of Sun) tweeted about this.[5] An official announcement was made August 1, 2013, with a last order in February 2014.[2]"
That said, that's a service I don't understand who would wanna use. There's no place like 127.0.0.1 (or ::1)
This is a very cool service, I just don't think the data security and compliance argument is a very good one. Unless they have some way of making sure that data can not possibly leave the virtual environment.
What if we ignored the NSA and security issues to think about the potential for new technology like this. If you never had to locally own your data, what could be possible?
How light could laptops become? We would no longer need as big of a hard drive and processor, and could probably reduce weight in lots of other ways.
And how many number of machines could you reduce to? Not only could two people share the same machine really easily, but you could access your personal workspace, work workspace, and any additional workspace with basically the same machine.
You'd just need to buy a lightweight device (similar to a Chromebook) with a screen. Of course they don't even support Chrome right now (IE and FF only), but the idea would be solid for almost anyone who doesn't game or need low-latency computing.
largely defeats the purpose if you still need a PC, license.
I know that EC2 and Rackspace has Windows machines, but only with Windows Server. When I have tried that, there is always something funny, such as IE security settings that are different from those of desktop Windows installs.
For now, I have settled on having local Windows installs (free licenses through BizSpark) in VirtualBox.
Fortunately for amazon, I think there's probably plenty of those companies out there.
Provisioning and renting out multiple devices, controlled via the AWS console (with some sort of address delivery form and ability to rent out devices, installed with a particular image).
I.e., allowing auto-provisioning to extend truly to the consumer space.
It'd be nice if there was a better way to transparently synchronize an entire VM and run things locally, since CPU and storage are so cheap.
That coupled with EC2 based infrastructure could make for a very compelling platform.
Introducing Amazon WorkSpaces.
Every single damn submission on the front page has some meaningless hand wringing over the exact same issue and it is 100% unproductive.
If you host your Desktop in the cloud at Amazon your data is completely at the mercy of Amazon. This can be an issue for health-related data or customer data.
It is a fact now that there are secret courts in the US that disallow Amazon from telling you that someone else accessed your data. I'm not sure about law enforcement but they can probably gain access to that data you stored there too.
As a business from a foreign country you lost control over your data. Some businesses can afford that - a lot can't.
As I'm in the UK pulling stuff out the US seems vaguely ridiculous if I move to another cloud provider anywhere as GCHQ has shown to be remarkably (frighteningly in fact) efficient (there has to be some humour in their about the government been more efficient at monitoring people than at just about anything else...) so back in house is pretty much the way to go.
I don't have anything that would interest anyone I don't think (We are a small company developing software for the renewables industry) but its not really about the nothing to hide mantra so much as restoring some of the balance and if that costs me a bit extra so be it.
Your company will always have to value the risk/reward tradeoff of hosting with a 3rd party and it has nothing to do with secret courts or any other silly end of the world predictions, and has to do with the fact that your data is outside of your direct control.
Where is the hyperbole? http://www.theguardian.com/world/the-nsa-files
> secret courts or any other silly end of the world predictions
As far as I know this is unfortunately not a prediction: http://en.wikipedia.org/wiki/United_States_Foreign_Intellige...
You may have no problems with these things. I'm not a US citizen and these things do matter in my decision to host my data in the US. These problems are not new. The US never had a strong privacy law.
Taken all this into account it's hard sell for any business outside of the US to use US based cloud services. That's all I wanted to illustrate.
What I am stating above is, NSA revelations or not hosting your data with a 3rd party is an obviously inherent risk.
Intelligent discussion about the issues of cloud computing, including data protection laws and spying, is useful and welcome. But posts that basically boil down to "LOL NSA" are not intelligent.
see here - https://news.ycombinator.com/item?id=6727500
My overall point remains: intelligent discussion like that is great, "LOL NSA" is not.
or honestly, even in just the hotel?
I've done this for years...maybe 20 years at this point. I can tell you this..."We" (meaning everyone in IT) don't do desktop management well AT ALL. I can't remember the last time I used a corporate baseline. They take 10 minutes to SHUTDOWN. (That's private industry...government is worse.) I don't know why users put up with it and it makes me realize why everyone hates Windows. (The average baseline literally forces it to stink like a rotting fish.) Couple that with networking guys that are useless at telling you anything other than "its up"...ITS ALWAYS THE FIREWALL.
Almost everyone that I work with just doesn't get how precarious their position actually is...if people don't want to use the sh!t that you work on you just might find yourself screwed at some point.
I work in IT and I would use something like this in a HEARTBEAT if it meant getting better boot times and less "what port is open" bs.
It seems to me that most people in IT actually think that the servers are more important than the people using them.
Thanks for putting up with this little rant...
Trust your users. If you can't, educate them. If you still can't, get rid of them and hire smart people you can trust. Now you don't need fancy "desktop management".
It's hard to believe, but IT is typically not in charge of hiring and firing the rest of the company.
By corporate baseline, I imagine it's corporate standard image with the standard loadout of software (encryption, antivirus, office, etc)
Believe it or not, most employees' job at most companies has nothing to do with computing. They use computers to execute some other responsibilities, but the computer is a tool and all they want is for it to be as easy as possible to use, and for it to "just work".
Even if you have a BYOD policy, you still need management around it for a lot of the reasons I listed.
Besides my own, I interact with our client's IT departments as part of my role. They run the spectrum from dysfunctional to superior.
Quite true but having interacted with a number of IT shops from startups to Fortune 100 / .gov scale it's quite disturbing to think about the percentage which could accurately be described as impediments and how few even realize this.
I imagine this is similar to what it felt like to work at a US auto maker shortly before the Japanese manufacturers started rolling.
Moving where the problems occur to a single "cloud" company that develops the expertise to solve these problems once for each of their corporate clients is a large improvement.
Companies will simply pay for cloud IT services that manage desktops, provide servers, and most importantly take care of maintenance and updates at a much cheaper total cost.
I think that "cloud" will be a definite bonus to the SMB shop, and provide a wonderful amount of spare capacity to enterprise shops, but I can't foresee "the cloud" replacing in-house IT completely.
But it will replace the major costs of corporate IT - technical resources services. For example, today a large corp (let's use Gazprom as an example) will contract a big IT services company (let's use Wipro for example) to manage their servers. This specific AWS service can in theory replace a large Citrix farm. When I was internal at SAP for example, every employee had access to their very own remote windows desktop, which had the basic office software on it required to do anything they could do on their laptop. The overall idea of cloud isn't the technology, it's that it's shared services.
Need a server? click a button Message queue? click. Database? click. Virtualised Desktops? clicky-clicky. Virtual Tape Drive? (I'm as surprised as you are).
You're still going to need people who need to know what each one of those things means to your business. But in-house enterprise IT today still consists of lots of people (and payroll) who put things in racks, re-image desktops, restore SQL Backups, install custom software and give the tapes to the dude in the motorcycle helmet...
In the medium term the cloud won't replace IT. It will however redefine it to the point that the 'spare capacity' that you mentioned will be seen like an amusing anachronism.
If I were a corporate IT/Security type, I'd have a firewall config ready and waiting for the day it becomes clear that corporate secrets (hopefully somebody else's first) are finding their way from employees GoogleDocs into competitor's hands. I'd quite likely consider the collateral damage of blackholing every Google IP address, including search (and advertising), to be easily justifiable in the campaign to keep corporate data out of gmail/googledocs/gdrive et al.
(I wonder if that's an opening for someone like DuckDuckGo or Blekko? Become "the search engine that's still allowed from behind corporate firewalls", because you're not offering the sort of end-run-around-IT-policies email/apps/storage that Google/Yahoo/Bing all have available?)
(As an aside, the possibilities for industrial espionage in your typical not-privacy-respecting search engine are staggering. Google knows what the R&D departments of every Fortune 500 company have cooking. Just look at the queries and clicks from their IP addrs. Yow.)
People decide to do something they shouldn't do, talk about it on GMail, and some "unfortunate accident" results in the deletion of said data when litigation time comes around and it's time to preserve stuff.
I wonder how their company's lawyer will react when presented in a courtroom with claim that they did not hand over all of the relevant employee e-mail in discovery. Further, perhaps they would like to read some of the correspondence for the first time as presented by the other sides law team.
Just because I can make the program, doesn't mean your shitty neighbor's son will care more about his job.
"How come these virtual desktops are about as common as bacon in a vegan sunday brunch"
ha ha!