Amazon Finspace - Security and Trust

    What a nightmare. This is exactly the kind of thing I'm afraid of with Finspace, and any cloud-based service.

    Somehow database keys were exposed, which allowed anyone to connect to any DB. Ugh... I wonder how bad it really is; how many breaches go unpublished, and what other vulnerabilities exist.
  5. If you look at Amazon's past behaviour, you'll see them doing things like asking one of their sellers for data on their suppliers and then cutting them out of the loop.

    I think the notion that just because a company is big, they wouldn't screw you is very naive.

    And as was mentioned, god help you if you ever happen to be on the wrong side of Amazon's politics, whatever those may be that particular week.
    I can understand that companies may decide that they no longer want to do business with a certain entity, but the way they booted Parler looked as if it was calculated to cause harm. The made sure to announce it around a weekend, and give them practically no time to arrange alternate hosting.

    Besides the issue of deliberate behaviour, there's two other issues to consider here:
    1) The cost to Amazon of your service being down is going to be much lower than the cost to you.
    2) There is an added layer of difficulty in trying to secure a "virtual" environment.

    It always amazes me how many companies and organizations are willing to use virtual servers that they do not own for critical business functions and sensitive data.

    If I was protecting particularly valuable proprietary data, I would use multiple servers thiat were owned by me with functions segmented, such that system exposed to the internet does not have direct access to the full dataset. The sever with the full data set would run a different OS, use different login credentials, and throttle requests such that the full data set could not be requested from the system exposed to the internet, and out of profile data usage would trigger an alarm.
    I sure as heck wouldn't do what some of these companies do and have a server with a giant file containing everyone's credit card and SSN connected right to the internet.
