Skip to main content

Cloud Computing Could Pose Serious Security Issues

cloud-computing-oracle
Image used with permission by copyright holder

(Editor’s note: This is the second part of a two-part series on addressing security risk on cloud computing. Click here for the first part.)

A few years ago, Google Enterprise president Dave Girouard had his laptop stolen from the trunk of his car at a San Francisco Giants game.

But if the thief was looking for information, he would have been disappointed. “There was nothing on that laptop,” he says through a spokesman. “Everything was stored remotely — there was no loss of data, and no loss of productivity.”

Girouard’s story highlights the potential of cloud computing, which experts acknowledge is still in its infancy. And Google’s Eran Feigenbaum advises consumers to “carefully consider to whom they entrust their data, be it on-premise or in the cloud.” But he says that Google is taking steps to ensure the data in their cloud is secure.

“Google has a full-time security team, and we employ some of the top security experts in the world,” Feigenbaum says. “Our operations work at a large scale, allowing our security teams to detect, act upon and resolve a wider variety of security threats than one single company would ever face – sometimes even before the threat is discovered by the antivirus companies.”

“With a traditional software vulnerability, a patch is released and companies typically take 30-60 days to deploy it,” Feigenbaum adds. “During that time, they remain vulnerable. With cloud computing, companies don’t need to patch their own servers. We designed our servers with security in mind from the start, and we can patch them quickly to help ensure our customers are safe.”

Christofer Hoff, director of Cloud and Virtualization Solutions at Cisco Systems, says he understands security concerns from both the business and consumer angles. But he also says the security issues are complex and they will be ironed out, in time.

“For the cloud service provider, there are questions of hardware, facilities, infrastructure, ability to build applications and software. Each of these has trade-offs,” Hoff says. “The business side is still maturing in this market.”

“For the consumer, it comes down to two things: trust and control,” Hoff says. “Cloud computing is about gracefully giving up control while trusting that a provider will exercise the appropriate due diligence and care of your information. The issue of giving up control is an emotional response – in many cases it’s a response formed around the opinion that a provider cannot do as good a job protecting one’s assets. We have to balance between control issues and making sure we have adequate visibility and transparency so that people can trust that the information is safe with these service providers.”

Hoff says these are some of the issues that will be addressed:

  • Privacy standards. “The challenge comes in the way in which these services are delivered,” Hoff says. “Privacy concerns in cloud are not that different from non-cloud service offerings although they are exasperated – because in a single-tenant, non-cloud environment you generally know where information is and how it’s being kept. With lots of different customers, that isolation of that data is appropriately maintained.”
  • Massive amounts of multi-tenancy and massive amounts of scale. “Providers have to manage service and isolation of potentially millions of customers and this presents a challenge as we see infrastructure and applications scale to address consumption at this level,” Hoff says.
  • “You have to take a holistic view (on confidentiality and privacy) and what the policies and service levels are,” Hoff says. “The standards I was talking about were less about regulations and more about open API and interfaces between cloud providers so that you have a choice of providers.”
  • There are 18 different organizations and standard bodies that are coming up with cloud standards and APIs. “That should settle down over time as a normal function of market dynamics and customer demand, but it’s very confusing and difficult at times to determine where to place your bets,” Hoff says.


Cloud Computing as an Operations Model

Amazon Web Services (AWS), which is also working on perfecting its cloud, has a white paper on how it secures its network. Companies that use AWS include ESPN, the New York Times Company and Pfizer, says spokesman Kay Kinton.

When asked about public vs. private clouds, Kinton says, “What we’ve seen dubbed a ‘private cloud’ is really just another form of virtualization and lacks the key benefits of the AWS cloud and Amazon VPC [Virtual Private Cloud]. Virtualization of an existing IT environment still means that you have to deal with the hassles of owning, managing, and operating the hardware – contract negotiations, facilities management, staffing.

“In addition, you still incur all the capital expenditure of owning all of your assets, instead of simply paying as you go,” Kinton adds. “Most important, these types of virtualized environments lack the key benefit of elasticity. With AWS not only can an application scale on demand but when the resources are no longer needed, an enterprise can release them and stop paying for them. It would be very hard for most enterprises to duplicate the scale and heterogeneity of use cases of AWS, and thus to simultaneously maintain high server utilization and the ability to scale up and down instantly.”

“It’s less about ‘what is the cloud?’ then ‘how can I use the cloud?’” Cisco’s Hoff says. “It’s still really early days in cloud computing. The technology is evolving but people are beginning to understand that the cloud is not a technology, it’s an operations model.”

Hoff also adds that Cisco is not looking to compete with companies like Google with its own cloud. Rather, its is focusing on enabling service providers with the infrastructure and solutions needed to deliver secure public cloud services as well as customers to build their own private clouds.

James Zipadelli is a Connecticut-based freelance journalist. He has written for CTNewsJunkie.com, Helium.com and several publications in Boston. You can find him on the Web at www.jameszipadelli.com or on Twitter @redsoxlive.

Editors' Recommendations

Ian Bell
I work with the best people in the world and get paid to play with gadgets. What's not to like?
This could be your last chance to buy the Dell XPS 17 (and it’s $600 off)
Dell XPS 17 9370 front view showing display and keyboard deck.

With the Dell XPS reset, the Dell XPS 17 has been discontinued. However, it's still a pretty reliable laptop by today's standards, and Dell's current offer the device may be your last chance to buy it. From its original price of $2,199, it's down to just $1,599 for savings of $600. This is a clearance sale, so once stocks get sold out, they may be gone for good. If you want this 17-inch laptop, it's highly recommended that you proceed with the purchase right away.

Why you should buy the Dell XPS 17 laptop
The Dell XPS 17 has been replaced by the slightly smaller but updated Dell XPS 16, but for a laptop that you can use for your everyday tasks, it's still an excellent choice. It's powered by the 13th-generation Intel Core i7 processor and the Nvidia GeForce RTX 4050 graphics card, combined with 16GB of RAM that's found in top-tier machines, according to our guide on how much RAM do you need. With these specifications, you'll be able to multitask between several apps without experiencing any slowdowns or crashes for a huge boost in productivity.

Read more
This HP laptop with 64GB of RAM is $2,080 off today (seriously)
Someone using an HP Elitebook laptop.

There are some laptop deals with low-power components for budget-friendly prices, but if you're looking for top-tier machines, there are some offers for those too. Here's one with a massive $2,080 discount -- the HP Elitebook 865 for $1,699, following a 55% discount from HP on its sticker price of $3,779. There's not much time left before you miss your chance at the huge savings, so if you think this is perfect as your next device, you shouldn't hold yourself back from pushing forward with the purchase.

Why you should buy the HP Elitebook 865 laptop
The HP Elitebook 865 is among the top-of-the-line machines of one of the best laptop brands, and this model comes with 64GB of RAM that will meet the needs of professionals such as engineers and professional audio/video editors, according to our guide on how much RAM do you need. Combined with the AMD Ryzen 7 Pro 7840HS processor and integrated AMD Radeon Graphics, this device challenges the performance of the best laptops with its ability to handle the most demanding processes that you can think of.

Read more
How to control your computer from your phone
Person using smartphone at home office desk beside open Chromebook.

Your desktop PC or go-to laptop doesn’t have to be out of reach when you’re away from home. Outside of tossing your MacBook or ChromeBook in a sleeve or backpack, there’s an easier way to access these web-connected peripherals when you’re on the move, and all you need is a smartphone!

What we’re getting at is called remote desktop access. This relatively simple technology (letting you interact with a virtualized version of your PC) has been around for a minute, but year over year, it continues to improve. That being said, there are specific tools and steps you’ll need to follow to ensure this mobile mirroring works correctly.

Read more