Showing posts with label cloud. Show all posts
Showing posts with label cloud. Show all posts

Wednesday, November 25, 2015

Social Engineering + Converged Communications = Bad For Security

John, I'm afraid I've got some very bad news for you.
We've recently learned that even the Director of the CIA can't keep hackers out of his e-mail. A teenager hacked into CIA Director John Brennan's AOL account. He says he did so by posing as a Verizon employee to other Verizon staff to get personal information about Brennan's account, as well as his bank card number and his AOL e-mail address. Then he called AOL and pretended to be Brennan. Armed with the information Verizon had just given him, he convinced AOL customer service to reset his password.

Brennan didn't have a bad password, he didn't e-mail it to anyone, he wasn't even tricked into entering it into a fake web page, the security failure here belonged to AOL and Verizon, and it wasn't even a technical failure at that. Now Brennan's e-mail is part of Wikileaks and a thousand articles.

Security experts including 360is have long since recommended 2 factor authentication systems for all of our clients, and yet still relatively few organisations have this kind of authentication. Their reasons? Cost, complexity, and (in)convenience. Over the last 20 years there have been a number of different companies attempting to tackle the three Cs, some of the more recent attempts make use of mobile devices and "soft tokens" on those devices, or they use instant messaging as a secure channel to convey some passcode or challenge/response.
Is there such a thing as too much convergence?

What if we are using multi-factor authentication, but thanks to the wonder of converged communications...all my factors converge upon 1 single device, normally a smartphone or tablet? What if that device were itself, compromised? Mobile devices can be cloned, rooted, or otherwise compromised just like any computer. How would that possibility change the level of trust you place in these kinds of multi-factor authentication? What if I am also trying to login to the secure service in question from that very same mobile device? If an attacker has my phone under his control, or has bamboozled me into doing something with it which help him, what happens to "defence in depth" and "fail safe"?

For these reasons, and because we don't think using 2 factor authentication should mean you have to trust a 3rd party organisation, we recommend keeping your factors as separate as possible for as long as possible. Talk to us if you want to harden your organisation against hackers, social engineers, and end users who sometimes make poor security choices.

Monday, September 03, 2012

Why VMware (still) Wont Convince The Cloud Providers


We don’t normally comment on commentary at the 360is blog. Most of our postings are more substantial, whitepapers, guides, seminars, or software we’ve produced or packaged. However there is a good posting (Cloud Hosting & Service Provider Forum) by Richard Talaber (ex-CTO’s office at VMware) on LinkedIn and thought I’d reflect on it here.

For those of you who aren’t on LinkedIn, or don’t want to join the group in question, Richard was responding to Beth Pariseau’s article at TechTarget on VMware’s recent abolition of the vRAM tax.

Richard makes the case that VMware is probably not going to be the right virtualisation stack for a commodity “$75” per-month per-VM hosting/cloud service, vRAM tax or not. He also believes that VMware still makes sense for the smaller market for high-value fully-managed VM hosting, with load balancing, monitoring, fault tolerance, and high performance throughput bells and whistles.

Mostly I agree with Richard, he makes sensible arguments supported by good assumptions but in-spite of this I still see more than a few problems for VMware in the short and medium term. Let me explain...

All service providers, including Cloud & Hosting providers, need to own their own infrastructure if they are to have a sustainable business. Whether it be a fibre optic network (in the case of a carriers) or their provisioning, monitoring, and management stack in the case of Cloud providers. Unless a service provider owns his own infrastructure, he cannot exercise full control over his costs. Cost control is vital in a service provider business, as profits depends upon volume, and any tax on profits is unwelcome, especially one that grows in-line with that volume.

Hardware must be paid for (hopefully using inexpensive long-term debt secured against assets you also own), but if there is even a chance of finding a cheap or inexpensive hypervisor-and-management-stack then Cloud providers have to take it. This is why you see so many of them with Xen, XenServer or KVM. This is why the list of users of OpenStack reads like a who’s who of Telecoms and Hosting. For those that argue I'm not considering TCO, think about this. I've hired good technical guys, pay them well, they work hard for me, I'm supposed to be a player in Cloud. If my guys can’t engineer something solid, maintainable, and cost effective then what am I doing in this business? These guys and the platform they build from KVM, Xen, or whatever, are my long-term competitive advantage. At least until I'm big enough to be building my own data centers from scratch.

If I'm a Cloud provider and my maintenance renewal (or any other per-unit-customer cost) jumps even 1%, its a big deal, I've got a bazillion systems after all.

For parts of the infrastructure that can’t be wholly owned, or cannot be had for free (with effort from my hardworking DevOps guys), the Cloud provider's only weapon is over-subscription. Pay for the product then figure out how to dilute that cost by maximising over-subscription, balance providing a great service with running the hypervisor and server hot. It is a very difficult balance. This is one of the reasons the vRAM tax was so wildly unpopular with Cloud providers, it took away one of their profit levers, or at the very least shortened it.

Hosting/Cloud providers are currently at a very immature stage in life, they are talking about RAM, and IOPS, and vCPUs or is it CPUs or is it Cores or Threads? What do any of those things mean? What about transfer rates, or latency, what kind of cores? What is a thread? These things don't mean much to business people so good luck trying to explain them. When business sees 3 prices for what they perceive as essentially the same service, they are going to go for the cheapest and find out later if it was appropriate. By Richard’s own admission, 80% of workloads are relatively modest in demands. VMware will not manage to get across an argument based upon performance; a performance lead of the size VMware achieves (or even aspires to achieve) is not a sustainable advantage for the Cloud provider market. 

Richard's last sentence is key: "Perhaps VMware should consider a public cloud price that is significantly less expensive than a private cloud price.". Logical. If the public cloud VMware price were somehow so small as to barely matter, then service providers would not spend time fiddling around with the competition or knocking up free alternative platforms....but how to segment the product? I think it is too late now, there are alternatives in-use, there are engineers out there with experience of building these infrastructures for service providers, and even if you can't afford to buy such people you can probably rent them. Talk to us.


  • Better performance is not a sustainable advantage for VMware.
  • A richer feature set probably isn’t either.
  • Cloud providers dislike anything that handicaps their ability to over-subscribe.
  • Cost that grows in-line with customer volume is a no-no, unless it is absolutely impossible to avoid.

VMware could make their product more appealing to commodity Cloud providers, but in order to do so they’ll have to start thinking more like them. Or talk to someone who does. 360is has helped companies like CheckPoint, HP, and Microsoft understand the Cloud service provider market. You know where to find us.

Thursday, December 29, 2011

360is End Of Year Message, 2011

2011 was another year of growth for 360is and for many of those with whom we work. Our base of Financial Services clients has seen a rebound since the darker days of 2009, and we have continued to expand into Scientific and Research Intensive sectors with several new projects and clients in Cambridge. As a result of this, we were pleased to welcome another Cambridge-based senior consultant to the practice. We continued to execute Virtualisation, Security, and Performance-related engagements for our clients, and maintained our focus on short term, (less than 3 month) fixed-price, projects, with a vendor-independent, client focused approach.

Inside 360is in 2011

  • Security work consisted mainly of Security Assessments, Penetration Tests, and Post Incident work, but grew to include Application Security Assessments, with significant new clients in the online gaming sector. We have also seen an increase in Distributed Denial Of Service (DDoS) mitigation projects. More companies with an online business model established themselves as brands, and therefore attracted the attention of extortionists, activists, and attention-seekers.

  • Virtualisation made-up almost 50% of projects, however the emphasis shifted from 1st-time production roll-out to 2nd or 3rd stage "3-5 years on" projects. We recently doubled the density of an already-virtualised estate of 500+ VMs as part of a hardware refresh cycle. Service Provider Virtual Desktop Infrastructure (VDI) projects also grew in 2011. 360is worked in partnership with client's Architecture and DevOps staff to deliver industry-leading high-density, high-margin, VDI to tens of thousands of users.

  • Performance-related projects were driven by a combination of CAPEX freezes and business growth, and were concentrated around storage systems. Due to continued difficult economic conditions in the UK, and recent shortages in hard drives, we expect this trend to continue into Q1/Q2 2012. In the last 18 months, data volumes have increased dramatically in Media (HD and 3D), Geo Sciences (ultra-wideband sensors), and Life Science (faster, cheaper, sequencing). These trends drive up data volumes and the demand for performance, as the bottlenecks move downstream.
360is Outlook For 2012

The outlook for 360is in 2012 is good.  Industry trends favour our long experience, technical capability, and vendor-neutral approach to problem solving. 
  • There will be fewer new infrastructure projects in 2012 (semiconductor sales were essentially flat in 2011). Supply chain disruption caused by floods in Thailand will provide even greater incentives to extend the life of existing platforms through careful optimisation and tuning. Although hard drive prices are stabilising, availability remains poor unless you take spindles as part of a large purchase from a major vendor. 360is can help you grow in spite of these difficulties, engage us to execute the following projects:
    • Storage Consolidation/Re-Tasking
    • Storage Performance Tuning
    • Storage Tiering

  • Rising energy costs and the practicalities of power distribution will continue to constrain some projects and have a significant impact on hosting and colocation costs. A recent study by 360is revealed that those renewing 3-year contracts for data-centre space typically saw a 40%-50% increase in annual charges, with colocation customers under pressure to migrate to higher-margin higher-price fully managed hosting contracts. If you have already virtualised some years ago 360is consultants can help you find an encore, we can further streamline your operations, deliver greater VM densities and lower OPEX costs through the use of new methods and technologies.
    • High Density, Low Power Virtualisation Appliances
    • Data Centre selection and evaluation
    • Cloud or hosting provider selection and evaluation

  • Recent wide-scale civil unrest across UK cities brought Disaster Recovery and Contingency Planning into focus in 2011. Further disturbances are set to occur as a variety of protest and pressure groups plan disruptions in 2012. Whether it be city-wide riots or attacks against individual organisations, it is now more important than ever to make sure you have a solid, rehearsed, Disaster Recovery or Business Continuity plan. 360is consultants have executed many of successful projects in the areas of DR/BC.
    • Secure hosting/colocation outside London
    • In-house Disaster Recovery Infrastructure
    • Replication and High Availability or Fault Tolerant Systems
    • Denial Of Service Mitigation
If your team is challenged to deliver any of these projects, 360is can help you do so, on time and on budget, in a way that is tailored to your organisation's individual circumstances. We look forward to working with you in 2012.

Monday, February 07, 2011

Welcome To 2011, Year Of The Rabbit

This year our normal New Year message to clients and partners comes exactly one month late. Another way to look at it (with the Chinese New Year starting February 3rd) is that we are bang on time.

一个好年头 (Another Good Year)
2010 was another year of growth for 360is with more clients in new sectors and a formalised datacenter performance practice. We deepened our profile in Private Equity with more virtualization projects (VMware and XenServer), and in mainstream Investment Banking with more VDI (VMware View and XenDesktop) assignments. Our Security practice continued with steady growth, and included new business from UK-based online gaming and "dotcom" sectors. 360is now counts among it's clients several of the UK's fastest growing and "best to work for" companies. While the UK Economy may have disappointed in December (particularly retail), through 2010 we saw our Financial Services, Mining/Metals, and Hi-tech Manufacturing clients rebound.

年更强 (Stronger In 2011)
The outlook for Q1 2011 is better than many thought. For the services sector at least, it looks like the December 2010 disappointment really was snow related, or was everyone at home with flu? This year promises more investment activity, increasing demand for raw materials (China again), and growing orders for our UK Hi-tech manufacturers.

We expect the trends of 2009-2010 to continue for 360is:
  • Increasing average project size
  • Steady rate of new client acquisition
  • Increasing number of projects per client
  • Steady geographical focus on UK, South East
  • Increasing client diversity beyond historic finance/telecoms base
  • Steady ratio of bookings to billings to backlog, no credit risk
  • Conservative recruitment strategy focused on "talent" not "resource"

科技是一个礼物 (The Gift Of Technology)
What technological gifts did 2010 bring our clients, and how can we best use them to increase their prosperity in 2011?


Multi-Core Systems
Multi-core systems have been around since at least 2005. One fact of which you may not be aware is that x86-64 CPU manufacturers have long since given up on making CPU cores go faster. Faster cores require more exotic materials, more expensive cooling apparatus, more complex micro-architectures with only marginal performance gains, and present all sorts of problems with manufacturing yield. That last point frightens shareholders to death. Instead, today, Intel and AMD devote most of their efforts to making more cores per square millimeter of silicon. More cores means more processing capability. Problem solved, right? Not really.
While increasing the numbers of cores (made possible as transistors get smaller) does increase theoretical performance, in practice this must be balanced with the right amount of memory bandwidth and core-to-core interconnect design. Even then, our problems have only just begun. The fact is most software does not take great advantage of multiple cores, more serious still is the fact that most programmers lack parallel programming skills. Finally, there are many classes of computational problem which are serial in nature, and are never going to gain much from running on a multi-core CPU.
Wont Microsoft/Oracle/IBM/VMware sort all this out for me? Not really.
While technologies like virtualization (whole-system or zone-based) allow you to run many workloads on a single CPU (keeping many cores occupied at once) they do nothing to speed up the execution of any one task or thread of activity. In order to speed up your IT from the end-user's perspective you may have to resort to more carefully considered system performance tuning, and that may require a deeper understanding of systems hardware and application software than your staff posses. The really big gains in performance can't be had by simply adding a product here and a patch there.
360is consultants have extensive experience in squeezing the maximum performance out of an infrastructure. Using a toolkit of repeatable intellectual property we are often able to increase performance even for serial, single threaded processing through our formal methods approach. Find out more about our performance practice.

Non x86-64 Servers And Other Novel Hardware
If like most of our clients, you are in the UK, then IBM Power CPUs calculate your insurance premiums, Oracle SPARC processors compute your taxes, and Intel Itaniums keeps your commuter train running on time (mostly). If you are out of work, then it's an IBM z10 CPU that you have to thank for paying your benefits. While Intel or AMD x86-64 systems dominate in the front office, the back office is more mixed, and with good reason. No, these particular systems do not run Windows, or Linux.
This year x86-64 front-office systems will be joined by new servers based upon ARM, Loonsong, Atom, and SPARC-T3 CPUs. So the next time you visit your hosted/colocated systems in a shared datacenter, keep an eye out for them. If you want to know how these systems might provide a competitive advantage to your business, get in touch. 360is has a record of working with novel hardware platforms that increase the profitability of our clients.

The Inevitable Spread Of Productivity Services
Technology vendor's continue to channel hundreds of millions of pounds a year from their marketing budgets into rebranding products and services "for the cloud". At 360is we call this "cloudwashing", it's much like the "greenwashing" that the same vendors underwent a few years ago. However, through the fog of cloudwashing there is value and real adoption happening in the world of cloud services. At 360is we are users of cloud-based productivity tools like Evernote, Dropbox, ManyEyes, and Google Chrome (as a tool to access other Google services). These productivity services offer an inbuilt ability to work anywhere, on any device, over any network. Whether or not they conform to your security policy, your users will soon be using services like these. If they make life easier then they will spread in the same way that instant messaging spread a decade ago.
360is can help you select and standardise upon productivity tools and provide secure remote access to your confidential information.  

VDI - Virtual Desktops - Desktop As A Service
Virtual Desktop deployments continue to grow in number as both large and small clients display increasing acceptance of this method of desktop delivery to end users. The primary drivers for VDI deployment remain:
- Avoidance of desktop hardware refresh 
- Ease of migration to Windows 7 from XP
- Stronger Disaster Recovery/Business Continuity
- Ability to manage/maintain more desktops with fewer/static IT staff
360is have executed a number of virtual desktop projects using all the major vendor products for large and small organisations in the public and private sector, using a variety of endpoints including thin clients, tablets, and mobile devices. Find out how.

If you would like to discuss any of what you have read about with one of our consultants then we would be happy to meet with you at your offices or at our London or Wokingham sites. Simply get in touch.

All that remains is for us to say is Happy New Year and finally"gung hay fat choy"(*)
(*)"may you become prosperous"