Using Amazon EC2 to Thwart Crappy Internal IT Services
cerebralmastication.com
cerebralmastication.com
One tiny slip, one mishap, and all of the "being freakin' awesome at your job" in the world won't stop you from being a great big minus sign on your company's balance sheet with regards to hiring you.
If you happen to be an employee considering these methods in order to improve your own awesomeness by breaking the rules, consider why those restrictions where put there in the first place: "jackass,you are the problem"
Sorry for the rant, just an old IT guy here who's had one too many dealings with over-clever users who broke stuff big time by "knowing better" without knowing enough...
My last employer had a good IT department, but also a strict security policy. USB keys were a no-no, so uploading company data to a third party wouldn't be favourably looked upon either.
Also we bought a software application that the vendor insisted needed unrestricted access to the internet. We tried it from behind our firewall and whatever they were doing couldn't get past our proxy. We actually had to deploy this internal application in a DMZ and waste a public IP to run it. We had a tech from that company doing some upgrades and later we found that we were running an FTP warez site. The tech had started up the default IIS FTP server so he could leave some files to retrieve later and didn't bother to tell us.
You aren't going to change policy with nose thumbing pranks. I have a decent win/lose record by engaging the decision makers over policy issues like this. When you don't win, you can't cry about it. You find a new job or live with it and wait for an opportunity to bring it up again. Playing tricks or willfully circumventing restrictions just makes it worse for everyone when you are caught.
Now, if Amazon or someone were to offer a variation of EC2 that did satisfy all the various privacy/data retention laws and regs...
/me scurries off to do some idle research
Of course I've worked around all these issues, but it's a PITA. I don't buy the legal issue argument as companies like google and msft don't have all these restrictions.
I'd love to know the reality on these legal issues. Is there really a legal reason for a company to ban IM/Chatrooms/iTunes/etc? If so, why is it that Google doesn't?
The bandwidth issues though I have no idea. Sounds like someone found the shittiest provider in your area and got a cheap deal, or greased palms.
Legal problem #1 with IM is logging. In public companies, particularly in regulated industries, anything that has ever been recorded by any employee can and will be used against you, and the discovery will come at your expense. Everything that is said, but NOT logged, will be used as evidence of your malfeasance.
For this reason, E-mail systems are typically centralized, and users are prevented from pulling mail off the server, so that all e-mail can be retained for exactly six months, no more, no less.
With third-party IM services, that can't be done. This is the reason for the rise of highly restrictive internal IM - Lotus Sametime, Microsoft office communicator. With Communicator you can ban both logging AND copy-paste centrally, at the server. It's a terrible tool, but it controls the legal risk quite nicely.
--
Google doesn't worry about this because they have more money than sense. (Also, not a regulated industry.)
I'm not in a regulated industry (enterprise software). I completely get this if it's healthcare or defense. But we are just talking about middleware here!
The costs of providing a high level of service are obvious, but the costs of lousy services are all hidden. As a result, yes, there's usually NO incentive to do anything more than the minimum.
(The minimum, of course, involves the ass-covering.)
There's a natural friction between developers and infrastructure. Developers consume the limited resources which IT has to manage. I've done plenty of both, and basically, both sides are correct. I recommend working on the "other side of the fence" for a little while to anybody in the industry.
Not to mention several state and federal regulations depending on the data being uploaded...
Granted you are being exploited, but some people will rather slave away than being seen as a greased wheel.
So he blames the company and puts sensitive corporate data up on an external resource with no ability to audit its security.
Brilliant!
Uh huh.
"The rules are there to prevent disaster, but as a consequence they ensure mediocrity" - http://www.youtube.com/watch?v=lA-zdh_bQBo
Sometimes no-disaster is all a big company wants.
Great tips for us teleworkers though.