16-07-2020, 04:27 PM
(16-07-2020, 03:56 PM)Mike Watterson Wrote: Which Cloud systems are independently audited?
Read "The Register". There are frequent breeches and downtime and data losses from all the major players. It's just someone else's server with a fancier and faster interface than text terminals in 1960s and 1970s.
And SMS is crap and insecure for MFA. They are all doing 2FA authentication badly. Many companies SELL your mobile number or automatically opt you in to marketing. Paypal is now using SMS. It's really lazy and stupid.
Cloud providers are continually audited by their customers and security professionals - my working life has been mainly in financial services and all the businesses I know do their own regular audits (or used a competent security company to do them). The ICO (and all competent authorities) recommend doing your own auditing plus clients often require regular independent audits (environments, pen testing etc.) as part of their own due diligence requirements.
As you obviously know, these environments are very dynamic, so regular (typically annual or semiannual) audits of those services used are always done. It's like water testing a well - you may know on the day of the test the water was fine, but the next night a sheep falls in... That's life really. Or not, if you were the sheep in question...
The "It's just someone else's server" statement is simply wrong (and has been for years). The whole cloud world has moved from just providing virtual servers to providing services, i.e. SaaS (software as a service) - the details of the underlying infrastructure are largely inconsequential and are often dynamically sized. Micro-service architectures now make the concept of dedicated servers seem rather archaic. Data is typically encrypted both in transit and at rest so the service providers have no access to plaintext at all.
Those providers that do just deliver virtual servers, e.g. DigitalOcean (who are excellent) don't complicate matters by offering SaaS - they offer virtual tin and networking in various forms at a very competitive price, typically for developers to create and test their cloud offerings on.
I'm not quite sure what your beef about The Register articles is - no environments can guarantee 100% availability of infrastructure and applications - that's what SLAs are for. You pay more for the additional resources and complexity those extra "9"s require, i.e. basic risk management and cost/benefit analysis. Oh, and backups are always a good plan.
Regarding "Many companies SELL your mobile number or automatically opt you in to marketing" - these actions are completely illegal under GDPR unless you explicitly agree for it to happen. The ICO's Guide to the GDPR is very clear on this (see GDPR Consent) as is the the source legislation - See Articles 4(11), 6(1)(a) 7, 8, 9(2)(a) and Recitals 32, 38, 40, 42, 43, 171. If you know someone who is breaching these regulations, I'd encourage you to report them to the ICO. Can you give a current example?
These are not toothless regulations, they are law in the UK (this is not just EU law, it's British too) and companies have been fined heavily by the ICO for breaches.
Lastly, something I'll agree on - SMS is not great for MFA. But (there's always a "but") it's far better than no MFA. A TOTP/RFC6238 based system such as Google or Microsoft Authenticator is better (plus maybe a biometric), but not always available. Again, sweeping statements such as "They are all doing 2FA authentication badly" are simply incorrect - there are other methods in use apart from SMS.
sıʌǝɹq ɐʇıʌ `ɐƃuol sɹɐ
ʞɔıu
ʞɔıu








