Sunday, April 04, 2010

My post on ReadWriteWeb

I recently had a guest post on ReadWriteWeb on security mistakes being made by users of Amazon's Web Services platform. If you use AWS, I encourage you to take a read.

3 comments:

Husein Choroomi said...

This is really scary! That's why I think every company needs at least one fulltime security expert.

Husein Choroomi said...

BTW, did you post something about your book, Electric Connections, somewhere? I didn't know anything about it until now.

Any plan for beta versions? Cannot wait to read it!

Jonathan Siegel said...

I think it's more interesting than scary. For instance--we now have a whole new set of usability concerns to investigate and optimize. In the case of my article, AWS has made two boxes in the datacenter closet. One box says "Your Private Stuff" and the other says "Stuff for the World to See." Most of us read the boxes before we drop our backup tape in, but sometimes a new guy tosses a tape into the wrong box. This is a metaphor of course, but you can see how no data center would ever construct this type of workflow--it's too likely to encourage a mistake no matter how talented their guys are. Similarly--you wouldn't make the WHOLE desktop area a trashcan in an OS. These are usability issues more than anything else--and what I stumbled across is a usability issue for the cloud. And then, because I get all meta, I wondered who should be holding the hot potato of the problem--Amazon, the vendors, us, or a as-yet-to-arrive-party?

And thanks for the book link. I'll be posting more over the coming weeks.