Amazon Starts Email Service for Companies
forbes.com
forbes.com
AWS is a lot like Linux that way: Deeply challenging initial learning curve, but the only thing worth considering for serious mission critical architecture. Stability and scalability does come at the cost of user-friendliness.
People often don't realize what a chasm of difference that is.
It doesn't help Google any that Amazon's customer service is _great_.
And beyond that, I absolutely don't want to have to rely on Google's customer support or pricing/platform stability for anything that really matters to me, and my company's infrastructure really, really matters to me.
AWS, I still <3 you.
http://arstechnica.com/information-technology/2015/01/amazon...
"Another notable feature of WorkMail is that users can specify what Amazon region their e-mail is stored in. Customers can choose a specific, relatively close data center to reduce latency in retrieving e-mail or for compliance purposes—such as European privacy regulations. The feature means that users won’t get the benefit of failover to another data center in the event of an outage, but Amazon may offer mirroring services later."
That is a big differentiator for many companies right there.
That sounds nice, but Amazon is still a US company, and the US government seems pretty staunch in their view that US law trumps country-of-residence law.
I'm not saying that is what they are doing but it would be a very interesting strategy.
Like for tax evasion vs tax avoidance, law enforcement cannot complain that individuals and companies use rules to their advantage, they just have to make smarter rules.
Require US companies to follow US law and regulations, across global legal entities, even when the local law of locally incorporated entities is incompatible with US law, absolutely yes, that is required.
Then why the hell would anyone build a company in the US?
In order to make e-mail into a system where two people can communicate in a secure fashion, where no data is stored on or passes through a remote system unencrypted, you would have to re-implement e-mail. And of course there goes interoperability.
The point you're making is whether 'state actors' can get into your documents or email. It's a different order of magnitude issue. First, as a company you're going to comply with whatever the law is in the jurisdiction. Second, if you're being attacked by a state actor then you've got major issues. And for many businesses even considering protecting against that wouldn't make sense from a cost vs risk perspective.
Addressing Office 365 Customer Concerns about Data Geo-Redundancy and Location - http://blogs.technet.com/b/uspartner_ts2team/archive/2013/06...
Where is my data? - http://www.microsoft.com/online/legal/v2/en-us/MOS_PTC_Geo_B...
This uses Amazon KMS. Amazon KMS is PC backed ("HSA"), which means all your mail is encrypted to a key which it now takes two Amazon employees acting under court order to get access to, rather than a court order and one employee.
Google's internal controls are at least this robust, and they have similar key management systems internally.
There might be a reason to buy Amazon WorkMail, but it's not for security advantages over Gmail.
Google's keyservers also don't have single employee control. The ones used for encrypting gmail behind the scenes, and other Google services. This is just table stakes for any large system.
This is in contrast to something like Azure Key Vault, which is HSM backed. A court order should not be sufficient to compel Microsoft to turn over a key from Azure Key Vault; it should be impossible for them (or for nCipher) to do so.
HSA is an Amazon term for a PC with an HSM inside. The data-at-rest might be protected by the HSM (full disk crypto with a dongle used to decrypt at boot), but the actual keys get decrypted into the host PC's RAM, and further customer-accessible calculations happen in the PC CPU.
Anyone who can tamper with the PC can read the keys!
There are two risks this exposes you to:
1) Someone goes into the datacenter and physically attacks the HSA.
2) Someone legally compels the owner of the HSA to subvert the HSA.
I'm not as worried about #1 (these are equinix tier-4 datacenters; someone rolling in with some M4s and a bulldozer and such is great for Hollywood. Insider threat probably still exists with the HSA even though normal operation is two-employee, though.) I'm incredibly worried about #2, since the bar for #2 is hella low for emails older than 6mo.
I believe ECPA older-than-6mo would be sufficient to compel the email KMS key as mere instrumentality, so even a the fairly low bar today of warrant wouldn't be required.
3) Exploit programmatic access or side-channel attacks on the data.
If the server can decrypt the data and this is driven by code on the box, then you're in a DRM-like situation trying to hide data from a program that has legitimate access.
As you alluded to earlier protecting data at rest doesn't protecting during use.
It depends on how you configure the HSMs whether you can extract and decrypt keys.
Why does it matter? They can certainly be compelled to use the HSM to decrypt data, even if they can't extract keys.
If you aren't doing client-side encryption and keeping the keys private, the server has access one way or another.
1) Where does this use Key Management Service to encrypt? At the SMTPD? With keys unique to each end user? S/MIME? What?
2) What's the real security model of KMS? Is it using HSMs for keys, or just shipping keys to systems? Does it use any other hardware/platform security features to protect keys, or just basically a "soft HSM" running in Dom0 on each machine? Or something purely network based, and also done in software only?
The more I have sat and thought about it, the more use cases I can come up with where there is a business case for it. One big one that comes to mind is foreign companies that don't trust the US.
EDIT:
That is, assuming the mail is stored on the server and it's encrypted, how do you search it efficiently?
It does not seem efficient to download every byte of mail, decrypt it, and search it on your local machine (especially a phone). Perhaps you could build an index locally, but could you keep it updated? And even that requires downloading and reading every byte at least once.
This is something I've always wondered about encrypting hosted email.
I guess it would be something like encrypting the index, then decrypt it on demand, just like you would decrypt individual messages on demand.
hashed-word => encrypted-list-of-msg-indices
something like that.
You can go under the radar when you are LavaBit small (and then, only until you have a single high-profile user). But not when you are Amazon.
Who says they're not pretending to get upset about them?
I want support and someone I can call, but I can honestly say that the support that I receive at AWS is more comprehensive and detailed that the typical response I got from Rackspace, which is really disappointing. Once I discovered that, I couldnt justify the 2x+ premium that I had been paying.
I also wish some of the more interesting things you have like Airbrake, Mailgun, Exceptional got more love. Instead, the focus seems to be on the non-differentiated stuff and all the "enterprise" stuff that matters less and less everyday.
What are the confidentiality provisions? Can they be changed without your consent? Does Amazon possess cleartext data and metadata? Do they monitor it to collect customer data? Who at Amazon can access it and when? What is their retention policy? Is non-retained data destroyed or just left on the storage medium until overwritten? How will they respond to subpoenas, warrants, and similar requests from counterparties in lawsuits or from government? And perhaps most importantly, how able are they to execute their policies and what deters Amazon from violating them (i.e., what is the penalty?)?
Is there any service that satisfies these requirements?
The 600 million contract described here is not GovCloud: http://www.informationweek.com/cloud/infrastructure-as-a-ser...?
After all, at a massive scale, having access to industry standard tools for provisionning makes sense: give $$$ to AMZN for their software stack and hw integration cost probably less than building your own...?
AWS GovCloud exist solely for this purpose: http://docs.aws.amazon.com/govcloud-us/latest/UserGuide/what...
A really private AV zone is just a step away: put gov guards at the entrance of DCs, replace all AWS teams by in-house personnel (or have AWS teams sworned in at the relevant level...?)
> Hard token multi-factor authentication (MFA) devices are not available in the AWS GovCloud (US) region.
http://www.theatlantic.com/technology/archive/2014/07/the-de...
1) a shared consumer service (i.e. a bunch of gmail accounts in the public namespace)
2) some kind of dedicated-instance-within app service (which seems to be how google apps for your domain works)
3) container/vm based isolation of app service (i.e. a provider who runs dedicated VMs of their own or standard platforms for people...I think some of the hosted exchange options are like this)
4) dedicated servers but with provider retaining root, but a third party or your own staff doing app administration on mail server
5) #4 but without root for provider, but with normal machines and thus singleuser
6) #4/5 with encrypted disk, such that it would be trickier
7) Colo vs. dedicated servers, with full crypto.
8) On-premise
I personally think the correct option for most organizations for mail is absolute-minimum 3, maybe 4. I feel uncomfortable less than 6. For someone like wikileaks, you are abjectly incompetent other than 7 or 8, at least using commodity technology today.
What sort of protection do they offer for phishing , spam and AV ?
Do they offer integration with other security , DLP suits ?
* Calendaring that Just Works, and a capable client for it. This involves an Exchange server and MS Office;
* You need mail that Just Works, and Just Works in conjunction with the above calendaring; this involves an Exchange server and MS Office;
* You need an easily controllable and relatively cheap OS that can run Word, Excel, and a web-browser for non-technical staff, and can be run on cheap-ass Dell boxes; currently this involves Windows and MS Office;
* You need a shared fileserver for people to upload company party photos to, storing improperly protected financial spreadsheets, and so on;
* You need a central identity system to tie the whole shebang together; this involves Active Directory
To summarise, you need:
* ActiveDirectory, for which there is now Amazon WorkMail
* Exchange, for which there is now Amazon WorkMail
* Windows File Sharing, for which there is now Amazon WorkDocs
* Windows desktops that can run MS Office ... for which there is sort of Amazon WorkSpaces
The question now becomes: can I get away with running a 200-person company with no relationship with MS by deploying cheap-cheap Linux machines with a VNC-client to Amazon WorkSpaces for non-technical staff? And the answer is ... perhaps, but I need my people to be able to work without an internet connection, so probably not.
But still, that's fucking huge.
The one piece missing in this lineup is capable local Office apps. You simply cannot get away with not having Excel, Word, and Outlook's Calendar functionality ... yet. Finance, Admin, Management, and non-dev IT will riot without Excel; Admin, Sales, and Management will riot without Word; Sales and Management will riot without Outlook, and blood will be spilled over the management of more than two meeting rooms. OpenOffice, LibreOffice, whatever, they don't cut it in the real world.
So while it doesn't sound like their game, if Amazon were to release a lock-down-able Linux and some high-quality Office apps, they can take SME IT away from Microsoft. That's is HUGE. Hell, if they can put together a package that can run Office under WINE reliably, and sort sensible licensing terms, it's just as huge, but I can't see MS allowing that licensing part to happen, because it would be suicide.
Interesting times!
[1] I don't care how Canonical or RedHat manage their internal IT
[2] Nor do I care about how your 11 person social media startup does it
[3] I too did all my best IT management before I became responsible for it
[4] Seriously.
Can't remember the last MS Word/Excel/Powerpoint document I've ever created. You could not pay me to run Exchange.
I tried to submit that to HN, but it didn't seem to work.
(Edit: Forbes’ article was much better than WSJs.)
That being said, I trust Amazon's data centers and API stack far more then Microsoft alone.
We've already learned this lesson with web browsers and HTML specs, maybe we'll have to learn it again for email.