Azure is now bigger, faster, more open, and more secure
azure.microsoft.com
azure.microsoft.com
Oh, that's right, how about more uptime?
Provider Outages Total Downtime
---------------------- -------- --------------
Amazon EC2 12 2.01 hours
Google Compute Engine 65 3.27 hours
Microsoft Azure VMs 102 42.80 hours
Source: https://cloudharmony.com/status-1year-of-compute-group-by-re...And this doesn't show the other Microsoft cloud services that have even worse reliability.
At my company we invested a lot of time trying to make Azure Service Bus and Visual Studio Online work. Both were so dreadfully unreliable as to be unusable.
http://www.computerworld.com/article/2865802/verizon-warns-e...
Number 49 out of 49 services.
If Verizon is offline for the entire time, maybe they'll be number 50.
As a side note, I'm not implicating Azure here, just a general context.
https://cloud.google.com/developers/training/exams/
??
See this is kind of an example of how Google is awesome at engineering but short on communication. I can't even explain how to get into their fold, so to speak.
And if you really care, try and find out the datacenter(s) your providers will be using and find out the historic performance of their different infrastructure and redundancy providers, and how often they actually test and upgrade their systems.
Look at the difference now when I filter by region and add the region data to the chart... it clearly shows just how hard these comparisons can be:
Provider Uptime Outages Regions Total Downtime
---------------------- -------- ------- -------- --------------
Google Compute Engine 100% 0 1 0 hours
Amazon EC2 99.9984% 7 3 0.13 hours
Microsoft Azure VMs 99.942% 56 6 2.89 hours
https://cloudharmony.com/status-1year-of-compute-in-america_...Maybe it's because we run linux server ?
One good point is cheap blob, slow but cheap.
* MS is managing said Key Vault, meaning they may well be under pressure from the NSA to provide access, without a warrant, and without a target knowing said access was requested.
* The local SSD storage can really only be used for temporary or cache based workloads... if your image ships to another machine in the case of failover, you'll lose that data. It's not a bad thing, but the High Performance (SSD backed) disk storage is still waiting for general availability, been on the wait list for preview for a while.
* The ready ubuntu+docker VM is cool, but I think it's more cool that CoreOS is generally available in the box now.
Ephemeral drives mean you need to change the design of your application to be able to withstand full loss of machines. But it's really not that hard. A good replicated database (riak, cassandra) spanning multiple availability zones gets you 95% of the way there.
Most C* deployments are in the 9-15 node range. You could safely deploy with 6 nodes and RF3 if 6 nodes gives you enough capacity in terms of both disk space and IOPS.
Let alone in the case of a more significant issue, and again, if the server goes down, that data is effectively lost, since the individual node will no longer be there. You have to have multiple sites and higher replication factors and a good backup system.
That said, Azure storage actually works very well, aside from the relatively recent azure outage.
RF 10 is insane overkill. There is probably someone out there doing it, but it is completely unnecessary for %99.999 real world deployments.
Getting back to your original comment, Azure persistent storage (or AWS, or Google) isn't giving you anything near RF10 * 2 DCs.
We backup all sstables to s3. We've never needed to restore a node from an s3 backup in 5 years of running in production.
https://www.google.com/patents/US20120321086
Anyone here speak patentese?
As far as privacy on their key store goes, I tend to trust Microsoft and Google more than average corporations.
Worse still, out in the real world as a client-facing consultant who uses a RHEL-based laptop for day-to-day work. I keep a VM of Windows 7 running for when I need to submit a document to a client, because there is no way I am taking the chance on Word interpreting an OpenOffice document correctly.
Right solution or wrong solution, Microsoft Office is the solution. I have to wonder where people work (and where they went to college) that affords them the luxury of taking a stand on what office suite they use. I would also like to know what open/libre office suite you're using where I can use the same document with the same file format and the same rendering engine on any platform including the web (where the web version is also open/libre). Because honestly I don't think it exists right now, let alone having existed for many years, which makes your entire point moot.
It's very bizarre to me that you're required to submit your assignment in a format which is only (truly) supported by paid software, as that would require all students buy said software. Certainly you could make the case that they could use the software available in libraries and such, but I see no reason that they wouldn't embrace more equality if not given the opportunity.
When I was in college, we didn't have to pay for anything to get MS products. The college paid for a "MSDN" library that provides students with access to many tools in MS's collection. MSDN is in quotes because that's effectively what it was but I recall it under a different brand for our college.
For IT students, we also had free access to all servers and client OSes, Office, Visio, etc etc etc. We never had to pay for anything.
This was true for the faculty, they also had free access to everything and that's why they require the students to submit specific formats.
Besides accommodating profs who don't use Word (the CS dept had a small but vocal minority of Unix graybeards), the other main motivation was to avoid having to deal with version compatibility issues. Opening a document created on one version of Word in another version would often (depending on the version pair) mangle some things, especially references and cross-references. And some files just wouldn't open at all. Things might be better with that now; I haven't had occasion to investigate in a few years. In the 2000s, there was a huge mess with the .doc/.docx transition, as well as compatibility issues between the Windows and Mac versions of Office.
Therefore "There is no other format that works as well as Word" is completely wrong. Relying on closed document formats and proprietary Software is shortsighted.
More broadly, in the business world, Microsoft Office is still very dominant. If your clients & business partners collaborate with Word documents, or Excel workbooks, or PowerPoint presentations, or whatever the case...running a VM so you can run MS Office and collaborate with them isn't "wrong" or something the parent needs to reevaluate- It's a business requirement and to ensure professionalism! It isn't nearly as uncommon of a use case as you think. I don't think he's shilling, he's being a realist given his needs.
But there's one thing he does know: sending an OpenOffice document to a client that is going to open it in Word is the fastest way to lose that client's business.
I have seen similar horror stories from AWS customers. They probably weren't early adopters like people on HN...who now have the kinks worked out.
MS should stop trying to impress the HN crowd. And unless you own stock in these companies you need to stop investing so much personal emotion in how they are doing compared to each other. AWS isn't some scrappy upstart from a Horatio Alger novel. MS isn't the Empire from Star Wars. And none of them give a damn about you.
> Building on our openness with the availability of the first Docker Image in the Microsoft Azure Marketplace
What the hell does "building on our openness" even mean in that context? I've read it several times and it makes no sense. It is great that they added Docker images (really) but maybe someone technical at Microsoft should start to proofread what nonsense that the marketing department spews out.
perestroika: ORIGIN Russian, literally ‘restructuring.’
In this case, Microsoft would be the USSR and its policy of closed-source Windows/.NET domination would be the old Communist Party hegemonic philosophy. That would make Satya Nadella Microsoft's Mikhail Gorbachev.
Does Google Cloud have the same functionality and flexibility that AWS or Azure have?
People have been saying "I'd rather stick with Evernote than Keep" as well. And less than 2 years later, Keep is still there and being updated (with not that many users I think), while Evernote had just laid off 20 people.
I also think most of Google's "spring cleaning" projects have been small projects that made no money - as in they didn't even have a business model (such as Reader). The cloud business seems to be pretty straightforward - we give you this, you pay us that.
What I mean is that if I want a basic VPS on Azure it costs ~10€/mo to run the server for the month, but there are many VPS providers who offer a lot better hardware for same price.
I guess Azure is meant for bigger needs than mine where you can run 100-200€/mo by default and then scale up when needed, but since my little blog + test/dev server won't need to be scaled it just seems too expensive.
ASW Cloud HSM - http://aws.amazon.com/cloudhsm/pricing/
Azure Key Vault - http://azure.microsoft.com/en-us/pricing/details/key-vault/
The metrics they use are not the same, so I am not sure if the AWS option is something dedicated vs the MSFT one is something you share? Is there something different from AWS that is more comparable?
I think it was good to have competition Apple/Linux/Google, but it doesn't seem like they've kept up.
It's a complete failure once you get lost in bugs, missing or hard to find API documentation or examples like `var serviceBusService = azure.createServiceBusService();` WELL Mister API Designer you failed!
YubiHSM back in the day, I recall reading, was designed so that you'd want two HSMs, one generates random secrets, the other stores the secrets using keys that never leave the device, if I recall correctly. And the reason it needed two is that the generator would leak parts of its keys with the random data it produced, I think, and so to securely store them, you needed a second device with key generating turned off. I could be out to lunch here, never bought a YubiHSM nor do I have experience with corporate ones. My point, is that there are different uses for HSMs, and it's easy enough to have an insecure use of HSMs, even as simple as generating secrets and storing secrets on the same device.
As to what to do if the key is lost, I suppose it's time to re-issue. :) The goal is to not make too many backups: keeping a key secret is more important than ensuring the key is widely available, right? So it's a balance....
Security of key material is all about procedures. With a private CA I helped to setup, we used a quorum based authorization scheme, and the collection of smart cards was distributed among different reporting lines to make collusion between employees difficult.
For more on the HSM service and how it works: http://blogs.technet.com/b/kv/
Granted, I'm only picking on Microsoft because they are announcing this now, and I think they could've done better. But I assume Amazon and Google's encryption also relies on "trusting them" (+ the US gov).
They all need to adopt more end-to-end solutions from end-user services to enterprise cloud services. Perhaps especially for enterprise cloud services, since I think they have more to lose by putting their trust in the cloud providers instead of building their own clouds, and they could be more reluctant to adopt their services because of that.
Maybe the cloud companies aren't feeling this as much now since there seems to be "growth" coming in anyway, but when the market will stabilize a bit, they will probably start feeling it. It's kind of how Blackberry didn't feel the they are banking on a bad strategy in the post-iPhone years, because they were still seeing "growth" during that time, mostly from other markets, hiding the fact they were using a bad strategy, and they were only growing because of brand inertia from previous years.
Granted, that solution wouldn't be as nicely integrated with their other services. I guess from a business POV, making it easier to be compliant with various security standards that require practices like encrypt-at-rest > building a solution that's secure even against state actors.
Very few businesses really have this requirement. End of the day, if the Feds show up with a warrant or warrant-like paper, I'm not going to jail for my employer. Hell, if I was locked up defending their data, I'd probably be expected to charge my accruals for my absence.
Source: http://weblogs.asp.net/bleroy/azure-web-sites-ftp-credential...
"Notice how the password looks encrypted. Well, it’s not really encrypted in fact. This is your password in clear text. It’s just crypto-random gibberish, which is the best kind of password."
What exactly is "crypto-gibberish"?
> What exactly is "crypto-gibberish"?
You generate a random password from the set of inputs that the system allows, usually printable ASCII characters. So instead of a non-gibberish password like "correcthorsebatterystaple" you end up with a gibberish password like "]'gf2~B;](0EnxW>/n%+b*q4{". > I'm pretty sure they haven't addressed the old issue of
> having keeping your FTP credentials in plain text.
Would you complain if it were an API key that was provided to you in plain text? "The Azure dashboard doesn’t seem to give easy access to your FTP
credentials, and they are not the login and password you use everywhere else."
Likely the difficulty of finding FTP credentials is because FTP isn't the preferred method of publishing your site.