Hacker News new | ask | show | jobs
by bearbawl 2006 days ago
This is very bad logic to be honest. When you have worked for some big companies, and I’ve worked for dozens and dozens of them, you know their security is basically Stone Age compared to anything in the « Cloud ». They have « firewalls » with rules nobody know about and wether they are still valid or not, they have applications running on servers they don’t know about (I saw in more than a single occasion that the « solution » is just to kill the application to see if someone is still using it), they have servers that they can’t locate, they have MPLS networks connected to remote locations with ZERO physical security (and of course the MPLS network is connected to their datacenters like it’s private network, i.e. with full access and no security at all), they have hundreds and hundreds of contractors with way way too much information, way way too much accesses, they have basically zero knowledge about what’s going on in the world of IT security, and they don’t have 10% of the people they would need to actually even try to do security, etc. etc. I mean, the security of those big companies is so ridiculous that it becomes funny. I suspect that those systems don’t crash more just because the hackers inside are actually maintaining them. There is no single doubt those companies would be 10 or 100 times more secure if they would move everything to AWS or Azure.
4 comments

Until some day, and you will get an article about a teen who was able to get access to any private message of any user just by asking the support for an access. Hum wait... already happened

Maybe the bigger you are, the more you think about security, but the bigger you are the more difficult it is to protect yourself

An organization that has spawned such a mess, and been unable to clean it up thus far, will be plenty capable of creating an equivalently insecure (but different in the details) mess on a cloud platform.
Yeah, and on the cloud they have all those things, and complete dependency on the security of the provider.
No they wouldn’t. They’d fuck up the same stuff in the cloud. I’ve seen it too many times already.