215 karma · joined November 25, 2009
http://www.cloudsigma.com/en/our-cloud/how-we-compare (feature comparison)
https://cloudsleuth.net/web/guest/global-provider-view (select Europe for a comparison of our cloud performance against other providers)
* Customer-managed firewalls
Yes
* Redundant switching/interior routing
Yes
* Private layer 2 networks
Yes we have private VLAN functionality. We'll be expanding this to up to 8 per server shortly.
* Bring your own IP space
Yes, this needs to be manually added to our BGP sessions but isn't a problem and we do this regularly for customers.
* Redundant exterior routing (e.g. I advertise my prefix through a new provider during an extended downtime)
We have multiple redundant carriers and they failover automatically. Actually the failover happens instantaneously, even if you are actively pinging you don't even get one dropped packet :-) If you have your own private infrastructure space elsewhere we also are able to choose the preferred carrier too.
* Out-of-band access
Not sure in what context you are talking about here. If you extrapolate I can give feedback.
"extensive network design customization that your managed service colo host will typically support"
could you give a couple of examples of the sort of thing you are talking about?
Can you think of other areas where competing services have common open billing? Great for sure but difficult commercially. Especially when you start bringing in credit risk and other non-technical factors.
If you see any of these zero value domains get registered you have your answer, or at least a very high confidence in your initial assumption.
In terms of what you say, we actually have many unique features and could no way be described as 'off-the-shelf'. We are continuing to innovate and will be launching future first-to-market features in the coming months.
There is a very big difference between a VPS where the vendor places restrictions on many things and retains full root access and our cloud servers were you have total control over the software running on your server and full root access.
Put it another way, if I gave you two servers, one dedicated, one a cloud server in our cloud. If you SSHed in, you wouldn't be able to tell me which was the cloud server and which was the dedicated server based on your control of the server. That's totally different to VPS.
Essentially you are combining the control of dedicated servers with the flexibility and transparency of cloud architecture.
Botnets etc. rely on free hijacked capacity not computing resources bought on an industrial scale on commercial terms. The cloud is no more prone for use as a botnet or other problematic activity than dedicated hardware. Although often touted, I've yet to hear a compelling case for IaaS clouds being any more susceptible to such use than VPS, shared hosting etc. etc.
Likewise, such activity becomes very obvious very quickly and it isn't access inside a customer's cloud server that allows you to spot such activity.
As I say, there are not real reasons not to give customers full control of their cloud servers any more than they have full control of their dedicated servers. In fact, the flexibility of the cloud makes policing it more easy than dedicated hardware without snooping inside customer servers or restricting their ability to control their computing.
In terms of administration, customers can choose to use their own in-house admins or that of a third party and many of our customers do. The point is they done have a choice, with other clouds they have one choice, the cloud vendor as the admin. That's overly restrictive and it isn't surprising why you get such concerns raised over security and control in the cloud.
Thanks for the great feedback by the way.
Best wishes,
Patrick CEO CloudSigma
Kind regards,
Patrick Baillie CEO
Our system is designed to let you control when servers are turned on or off in order to perform orderly computing. Likewise the fact that the servers and drives are persistent allows you to shut them down and back up again over peak times and keep data persistent. This is great if you are doing large jobs like 3d rendering for example.
Best wishes,
Patrick Baillie CEO
Kind regards,
Patrick
Best wishes,
Patrick
For those deleting virtual drives in the cloud securely the points made in the post might seem obvious but I believe most users in the cloud don't undertake such measures. That's why the encryption option is another way to go and implicit so much more likely to be taken up by cloud users.
Customer side encryption is great and of course usually means access is restricted to the customer, the issue is server restarts, crashes etc. which require manual intervention to get the file system or data directories back up and running again. In a dynamic cloud environment this can be particularly cumbersome.
Best wishes,
Patrick
Of the first point we outline how data leakage is possible in IaaS clouds. Some may already have measures in place to prevent this. We have our own measures too, some private others public. We offer encryption also as a free and convenient way to secure your data. This has nothing to do with securing physical access which is a totally separate issue. It relates to how customers secure access to their data. As outlined previously we don't have root access or file system level visibility into cloud servers in the way that other vendors generally do (although there are exceptions). As such it does pretty much come down to securing physical access. That isn't the case on other platforms for sure.
Here's another article that you might like (short but sweet) which actually talks directly about EBS and others and the problem of 'data remanance' in a way we can't as a competing vendor:
http://elastic-security.com/2010/01/07/data-remanence-in-the...
Here's an interesting quote:
"The technique of overwriting file sectors does not work without the collaboration of the cloud provider. You are not given access to the physical device, but only to higher level abstractions like file-systems (e.g. Amazon EBS) or key-value based APIs (e.g. Amazon S3). "
I'll get back to you on the loopback technique once I've spoken with the relevant storage guys in our company for feedback.
Kind regards,
Patrick
The issue there is more about tracking. You'd have to track every single block and return zero for any that hadn't been used/altered since drive creation. I'm guessing it would prove pretty costly in terms of latency for drive access after initial drive creation but its a good idea potentially. I'll pass it onto our technical guys as well to ask about its feasibility.
Best wishes,
Patrick
"there are more efficient ways than encryption or "full sweep overwrite" to address this at the storage-level."
Your suggestion would be?
Kind regards,
Patrick
Firstly we can't comment on the arrangements of other companies for whom we don't have visibility. As a customer you can of course ask them and one would hope they are able to provide you with a full answer. On the blog we raise and answer (in our case) the various aspects for data storage, not just of security but also legal issues and data migration aspects. How many customers currently using an IaaS cloud can answer those questions or get their vendor to provide answers? Building confidence in cloud computing is all about transparency, education and creating secure ways of working. Different users will choose different solutions and regimes that they feel are 'secure' for them and we are all for that. We'd also like people to be able to make informed choices which means having the right information.
Secondly, there is a big difference between a vendor that has sole root access and full visibility of all your data and one that doesn't (as in our case); in our cloud the customer retains sole root access to cloud servers. This means our employees don't have visibility into cloud servers in the way you suggest. Further, as clearly stated in the blog, the issue raised is about data leakage i.e. data being accessible between cloud users. There are other issues regarding vendor security but this doesn't negate the points being made about data leakage.
Finally, your point regarding the encryption being a placebo is specious. There is a big difference between making systems secure against casual data theft/leakage or the actions of rogue employees and a company that is institutionally set up to lie and steal their customers' data. If you think your vendor is actually of that nature then no security measure can help and that's the case for any company you have dealings with. It really isn't a valid criticism of any security measure that may be put in place.
The measures we outline and have implemented on the vendor side do address the real issue of data leakage that occurs with block storage devices in IaaS clouds; they are effective and they are convenient. Our storage performance is generally higher than many other vendors to begin with and we have much feedback from customers regarding this even after using encryption. These customers are getting good performance in a secured cloud. For them it makes sense.
Best wishes,
Patrick
Best wishes,
Patrick
You say encryption is complicated but actually as a vendor its implicit in our system. As a customer you just mark the drive upon creation and then its invisible to both you as a customer and the cloud servers that are using the drive. That's really the whole idea, to make security measures that are convenient so people actually use them. Our customers see usually about a 10%-15% performance difference and we've got pretty high storage performance to begin with so it rarely means taking a performance hit compared with other platforms. We also allow multiple drives so users can categorise data by drives for encryption or not. Of course I'm biased regarding performance but the principles stand.
The other point of the blog post is to ask; what do other vendors do and do their customers have the ability to find out? Security through obscurity isn't an acceptable approach in the cloud. Everyone needs to be transparent and work to build confidence through solid information and education on how to use the cloud securely and effectively.
Kind regards,
Patrick
Storing encrypted first does affect performance but it is generally much less and more predictable (doing a big secure delete on a drive inflicts an immediate and unexpected hit on that part of a storage array).
We think encryption is also just a lot more robust. If you don't lay down the data in the first place in readable form on the physical drives, its eliminates a lot of data leakage possibilities.
Best wishes,
Patrick
As a Swiss based cloud currently we'd be excluded from many US industry sectors which required domestic hosting. This will change shortly (can't say more) and when it does we'll be working to put in place the necessary coverage/compliance certificates to expand into these sectors.
Best wishes,
Patrick