Showing posts with label Cloud. Show all posts
Showing posts with label Cloud. Show all posts

Monday, August 13, 2012

Episode 23: Cloud will never oust the desktop as Mayor

Yup. You did just read that on a Cloud professional's blog. And I meant every word of it. And it's true too. The cloud will never replace the 'desktop machine' (or 'localised IT infrastructural assets' for those who want to be pedantic & play along at home!). And before you say it, your friendly neighborhood cloud sales person isn't right. Your friendly neighborhood cloud sales person wants to sell you services, & all the spoils that come their  way for making their targets. And they've just read that opening salvo & gotten annoyed by it. Very annoyed.

The cloud is very good at a great deal many things. Sure, it can simplify lots of complicated purchasing into 'consume-on-demand' ICT in nice neat easy-to-use services. Sure it means you're not making CAPEX spends in such an indefinite set of economic & trading circumstances that otherwise kills your ability to be flexible to the market. And sure, it means you can offload some expensive aspects of your requirements to being someone else's problem as a managed service. And they're all very laudable selling points.

But, and this is the biggie - Cloud has become something used BY the desktop. That's right. Cloud is an augmentation to the desktop. Access to cloud services still requires a machine with an OS, with storage to install accessibility software of some sort (browsers, VPN clients, dedicated applications etc.). Even on your mobile devices, you're still dependant on them carrying the traditional 'desktop-architecture'  to access your cloud for management or productivity.

And no, desktops in the Cloud isn't the answer. In fact, it's damn near a non-runner. Purely aspirational in-fact. And Why? Much as there are those who are loathe to admit it, Microsoft owns the market when it comes to productivity computing. They also don't allow their Windows desktop licensing to go near ANY form of multi-tenancy solutions for hosted desktops. Sure there's OnLive, but that is a riddle wrapped in an enigma wrapped in a giant 'how-in-the-hell' blanket.

Given the cloud as a whole is multi-tenancy, unless Redmond reverses its stance on Windows Desktop licensing, this will never happen save for those few businesses who implement on-site virtualisation, which will be for reasons other than cost-effectiveness, but only at the 500 seats or more space.

And no, it's not realistic to expect or suppose there'll be a shift by everyone to using a Google Chromebook, or even to ClamCase's laptop dock. It's just not going to happen. Nor is it realistic to expect that everyone is going to shift to tablet computing eschewing notebooks or desktop machines. There's too much of our daily computing lives in the world that simply will not transfer to mobile. That is clearly visible in markets such as MMO gaming with 9.1m players of World of Warcraft, or the 1m players of Star Wars: The Old Republic, or high end games such as EVE online. If anything, mobile computing devices are simply companion devices. Yup, I just said that too - you didn't misread.

Tablet machines are great for low-interaction computing needs from wherever you find comfortable - be it on a giant bean bag, at your favorite coffee shop, or your favorite park on that bench in front of the lake with the ducks, or even lazing on your couch. Smart phones are in the exact same boat. But I can tell you that you are not going to knock out your end-of-year accounts on those devices. Sure, there are some who will say "But Ian, I do." And if you're one of those, good for you. But you're in an extreme minority that isn't growing, nor will it.

And the most important fact is that people fear change. People will not willingly give up the security of their disks in lieu of those in the Cloud. Cloud writers/gurus/warriors/evangelists/bloggers/watchers often live in a world which is purely aspirational, not filled with FUD (which is often perpetuated by cloudwashers & marketeers), & where their ideals exist peaceably. It's a mind share that right now in the current climate just cannot be overcome by slick-salesmanship, good marketing or even divine intervention. And historically, it's an easy to prove case also.

The cloud while nothing revolutionary, does have many chops that can help your business. It can become a very good friend to your business. But, the cloud will forever be just a drinking buddy to your 'desktop'. They'll be best friends. They'll get drunk together, sometimes sing some great tunes while getting along famously, other times they'll fight like a pair of rummies & not talk to each other. But, they will become closer & share even more with each other. And, we will all look on like concerned friends, continuing to wonder how it will all end. And the cloud should accept that. So should you. And your friendly neighborhood cloud sales person.

Tuesday, August 7, 2012

Episode 22: When the rain from the cloud is just your tears

The tale of Mat Honan's remotely wiped Apple products has now been committed to the lore of the Internet. But this tale as with any comes with a proviso that has long been the anchor of the 'superhero' story; "With great power comes great responsibility." Our reliance on technology as the super-hero in our modern life has set us up for spectacular falls, akin to any great fallen-hero story-arch.

We have great power in our hands with our smart phones, mobile devices, cloud-enabled hand-held & remote technologies, & yet we wield these powers with little to no real responsibility. Mat Honan originally supposed that his accounts were brute force attacked (something he later retracted), but days later we learn they weren't. He was the victim of social engineering; the attackers rang Apple support, managed to pass through their security protocols due to "Apple's centralised single user account approach."

Blaming Apple is easy, but the fact is we are seeing further centralisation of our online lives with more & more of our accounts & services being linked together via our Twitter, OpenID or Facebook accounts. Each node we link in this way just increases our vulnerability. With security compromises of user databases on the rise, our entire 'digital life' faces compromise from any one of the countless services we interlink.

But that's not even the bigger risk. Publicising information about ourselves in such a carefree manner on social networking sites gives 'hackers' (calling them this when we make it this easy for them denegrates those who are 'real' hackers) less work to do when searching for information to use against us in a social engineering scam, when they wish to target someone.

The real threats as a result of our digitalisation is not our own personal Twitter, Facebook, LinkedIn, or Tumblr accounts - the real risk is our employers, & our businesses. As we increase the drive towards BYOD, our personal & business accounts become increasingly intermingled, something Honan discovered when his employer Gizmodo experienced as part of his account compromise, where tweets from Gizmodo were sent by the hacker.

Very few security breaches today are carried out by brute force. Most are the net results of social engineering, or end user stupidity - the breaches of Irish Department of Foreign Affairs systems by people linked to Anonymous earlier this year showed that stupidity really was the over-arching issue, with passwords such as 'Password1', which demonstrated two failures;
  1. A failure culturally within the Department of Foreign Affairs ICT to educate users about the security of ICT systems, & to ensure a clear understanding of the requirement to always operate a 'strong password' policy
  2. A failure of the users themselves to understand that given the sensitivity of information they handle from where they work, that security should always be to the forefront of their thoughts when working within ICT systems
Security breaches are often where 'hacker' opportunism meets 'end user complacency'. I have always maintained that the biggest threat to any business is not external, but at every level inside a business, even more so at executive level. Social Networking as powerful a tool as it is for good to be used by us, can just as easily be turned against us at a moments notice.

To protect you from yourself, there are a few simple steps I would recommend & suggest:
  • every time you "link" a social media account to another account or app, ask yourself "Am I really happy with this connection being made permanently? What's this company's history on security like?"
  • If you authorise an app to link to one of your social networking accounts, regularily review that connection - if you don't find yourself using it often, revoke access until it is absolutely needed again - don't leave authorisations blindly open
  • Who can view your social networking streams? How much information do the reveal about you? Perhaps the only people who should see your streams are those you know, & not the great wide world.
  • Are your personal passwords themed with your work password choices? If they are, address it immediately. 
  • Do you save passwords in your browsers, or directly in applications? If so, remove them. Then change your passwords.
  • Is your password comprised of a word with numbers, even with capitals? If so, this is hacker101 from a dictionary list. Even words where letters are replaced with numbers are straight from hacker101; i.e. 'l33t' should ring a bell with most.
  • Do you use the same password for multiple services? If so, this is a rookie mistake, & often how many online gamers accounts get compromised. Using the same password or variants of over & over is just putting you one step at a time closer to getting burned. Badly.
  • Ask yourself can anything I reveal or have revealed on my social networking sites help lead someone to one or more of my passwords? If your answer is 'yes' or 'I'm not sure', you've a problem you need to address.

Friday, March 30, 2012

Episode 21: Your legacy in the cloud & your rights (or lack of them)

As we shift more of our lives onto the Internet, & thus into the Cloud, we commit our lives either unconsciously for some or fully in the knowledge for others to big data, big business & profits for big business. It has long been sci-fi lore that humans would interface with computer systems uploading their vast knowledge & consciousness to cyberspace to 'live forever'.

But we don't. We die. And when we pass on, there's an estate that is disposed of either via a will with an executor etc, or via the granting of a letter of administration. But, our worldly possessions now are not just limited to the contents of our homes, bank accounts etc., we're all actually the rights holders to our information, our likenesses, & our works we publish on the Internet (unless you sign them away like FaceBook's terms & conditions).

For a long time in the 20th century, loved ones left behind photographs, slides, books, journals, diaries, mementos from trips, postcards. In the 21st century we're looking at Flickr albums, FaceBook wall entries, Twitter accounts, FourSquare pins, GMails, & countless other digital footprints from our lives. Even our own hard-drives of photos, movies, & music. The legacy of our lives can now be measured in ones & zeros. And with many of these future legacies, a problem arises; access to them to retrieve & pass on.

To use one of my own examples, when my maternal Grandfather passed in the mid 80's, he left an absolute treasure trove of things; photographs, negatives & slides from his countless travels around the world, some of his books with his notes written in them, some of his naval belongings - many of which today, I treasure greatly.

Zip forward about 25 years, & I look at my own little collection. Up until around 2000, I've a fine collection of photographs & negatives, along with trinkets & some writings from countries, cities & towns I've been from around the world. However, after that I'm seeing lots of digital photographs, my musings/writings are exclusively digital. I've e-mail accounts I've held going back to as far as 1995. I've a fantastic collection of gaming moments across a number of MMO games I've played (and some I continue to play today), along with many other exclusively digital assets.

As I go on in years, these will no doubt increase substantially. And when I inevitably pop my clogs, I will have to ensure I've a list of password details written down somewhere to allow my loved ones retrieve everything. But, what happens if something happened before I had time to plan for this eventuality? Should I already be creating a password safe of sorts? Convention on security would tell you creating one of these is absolutely insane, yet on the flip side, how else would loved ones retrieve everything else? It's not as if they can ask the service providers to hand over the data, as the contracts of use are between me personally & the providers, it's not like financial assets after death that form part of an estate.

Which brings on the more interesting question; while our personal data is recognised in data protection acts as our own, should our personal data now in turn form part of our estate legally? Should there be provisions for this in data protection legislation?

In the UK for example, 'property' when dealing with a dead person's estate is defined as follows:

"'Property' includes houses, real estate generally, shares, antiques, jewellery, works of art, and intangible property such as patents and copyrights."

and according to UK law, access to that property happens as follows:

"If the deceased held property in their sole name, and they left a valid will dealing with the property, the property will usually pass in accordance with the will. If the deceased left no valid will, or a will that did not deal with the property, it is dealt with under the law of intestacy.

If the deceased held property with another person or persons, the deceased's executor or administrator needs to find out how the property was owned. Where the property is a house, there should be written documentary evidence of the type of ownership
."

In Ireland, under Ireland's own 1965 Succession Act, property is defined as "includes all property both real and personal", & none of the references seem to make direction to copyrights and or patents. part of the problem globally seems to be the lack of establishment by courts how some one's online services relate to transfer to estates upon their passing. This is not a new issue. It is an issue that has been questioned for a number of years, & a really good example to read is Thomas Scrampton's piece in 2009.

One of the leading writers/speakers on this area is Lillian Edwards, who is currently Professor of e-Governance at Strathclyde University. In mid 2010, she gave a talk at Wolfson College about 'Death & the Web', which raised many interesting statistics. More recently it has again come up for discussion, with Laurence Eastham writing about it for SCL, which was prompted by a press release by UK law firm, Rothera Dawson Solicitors.

And yet, in Ireland as a country pushing forwards as a central player in Digital Europe, apart from us having our cyber security act buried on some civil servants desk now for over a year in the life of this Government, & unimplemented from the last residents of the Government offices, there is no discussion about us moving this important area of legislation, or legislative discussion forward.

It is all well & good to push the agenda of Ireland as a centre of cloud excellence & influence, but if our legislation around data in the cloud continues to be woefully inadequate due to ill informed politicians, civil servants with their own agenda of 'not rocking the boat' & businesses who in general have a poor level of awareness of data protection & their legal requirements/compliance, & a no-one in the legal sector even spotting this is a ball that needs picking up & running with, we are heading for a massive storm amongst our clouds.

As the cloud finds itself becoming part of the discussion on rightsholders & their legal reachs via SOPA/PIPA/ACTA etc - why are we not asking for the rights to our own creations/works/digital assets to remain with us? Surely as the discussion about privacy is front & centre to the Cloud & digital media/social networks, our rights to our own content must become part of that fabric of discussion, & part of the discussion as 'rightsholders' in our own sense.

Saturday, December 31, 2011

Episode 19: If Prof. Trelawney did 2012 cloud predictions, it would be these.

2012 is mere hours away. A new business quarter looms, & Irish cloud companies will be gearing up for the traditional January assault on the market. With the last twelve months behind us, & a new year to look forward to, 2012 is the year that will make or break the cloud in Ireland. As such, I've taken a look ahead at what I believe the next 12 months will hold for the cloud computing market.



1. The continued rise & rise of the enterprise app market
With thriving markets for Apple's iOS devices, Android, Google Apps, SalesForce Force.com, & Amazon's App Store already mainstays, 2012 will be the year where AppStores will take off in the enterprise space, providing Cloud services to replace traditionally more expensive pieces of software. This will come from the growing PAAS space, where developers will build out on these platforms. If Google Apps is anything to go by, there will be a big push in this space for enterprise from the big five.


2. PAAS growth
With AppStores taking off, PAAS players will be rubbing their hands gleefully. Long gone are the days of issues over OpenSource VS Microsoft. The real power play is going to be in who provides the better incentives for developers financially. Sure, Google's Android market has more Apps than Apple's, but Apple makes a better payout to developers, & more often. It is also widely acknowledged for having better earning potential for developers. People in the PAAS area turning to the enterprise App market will be aware that having a great App is not enough, enticing people to use your market & make it worth their while will be the key.


3. More mobile & tablet computing
We're starting to see the death of even netbooks with Dell winding their offerings down, & the real focus is on the mobile & tablet computing side of things. With these access points being so focal in the consumer market, it is only natural that adoption in the enterprise area will follow, which will go hand-in-hand with an explosion in the enterprise app market in 2012. The frantic increase in the lawsuits over IP in the tablet/mobile computing space right now across the globe should tell you everything. For the big players, we're at the forefront of the latest technology warfront. Control of the battlefield is essential to how platforms, app stores, developers & the future of the technologies in the enterprise space is at stake.


4. Less Private Cloud discussions
As far as I'm concerned, the debate over private cloud is well & truly over. Private cloud doesn't exist. Call it what it is; virtualised consolidation of private environments. This contentious area of the cloud has been debated ad-infinitim, & has been murked by vendors who were silling these kind of solutions against what are accepted cloud solutions as a means to show a value against what are often cheaper competitive solutions. Private cloud in 2012 will become part of the 'do you remember when' types of discussions, as opposed to constructive parts of discussions about where the cloud goes from 2012.


5. More consumer cloud solutions
Between Google & Amazon's music lockers, iTunes, iCloud, & Microsoft recently announcing they were seeking to bring on more cloud services for their mobile OS users, & Nintendo sneaking an App store under the radar, things are moving at a freight train pace for consumers. Digital Television is finally coming into the fore across Europe, so expect an explosion of cloud-based consumer services for the consumer, including TV-related ones, especially following the US court ruling that TV/movie content uploaded into cloud lockers by consumers is not a violation of copyright law. With Apple rumoured to be releasing a range of televisions in their own unimitable style this year, & With SOPA coming under increasing pressure publically, consumer cloud will continue to be the canary down the mine for Cloud services, which will eventually cross over into the Enterprise.

Wednesday, November 16, 2011

Episode 16: Knock knock. Who's there?

Security in the cloud. This is the re-occurring theme when the technology conversation turns to cloud computing. Usually that's followed by "Where's my data?" or "Who can get access to my data?" or "Do I have complete control of my own data?" Security in the last twelve months has become the real deal breaker, & issues experienced by a high profile name in the technology world like Sony really made alot of people who have been on the fence about whether to take some of their business critical systems into the Cloud.

Recently, the Ponenmon institute conducted a study that revealed that 67% of the IT professionals questioned admitted that their respective organisations were vulnerable to hackers due to lax firewall security. Scarier was that 42% of those surveyed said that were they breached or attacked, they'd have no way of knowing what was compromised. And it got worse with over half saying they were of the opinion that their staff had no knowledge about the potential risks of open firewall ports.

The full insights of that study would appear shocking to those outside the Cloud Computing industry, but to those in it, it's not, but it also isn't the full story. The study neglects the real root of the issue; good security governance from the desktop upwards in any infrastructure. The truth is, there seems to be a general lack of knowledge about security & the implications of security issues from the receptionist to the CEO, with no-one seemingly taking full responsibility for it. No-one drawing a line in the sand about where the buck truly stops.

People leaving their screens unlocked, downloading software, or opening e-mail attachments without care, providing the opportunity for those out there to re-enact a digital version of the siege of Troy. There's even less of a responsibility taken by those who code websites, or are designers-for-hire. Many don't seem to understand the platforms they are building for, or understand how the applications they design & build for clients work in the cloud.

The issue really comes down to one single fundamental questions; would any of us leave our wallet down for anyone to peruse at will or take? The answer is no, we wouldn't. Data in any business IS the wallet of the company. It has to be given the same reverence, respect & care. Sure, the questions about where your data is, or who has access to it are valid, but the real question any organisation must ask is simple & stark; do WE ourselves treat our data the way we expect our service providers to treat it?

As sure as you could establish a cloud solution with a cloud service provider, then pen test that to within an inch of its life, the more important pen tests need to be done within your own organisation. One of the continually growing areas of access compromise is people taking advantage of social engineering; the process of obtaining information and or access through deceit.

 People are still taking calls from people claiming to be from well known technology companies to run pieces of software on their machines, only to later find themselves compromised, exploited and or defrauded. People are still clicking on links in e-mails telling them to log on & confirm passwords. Ask any online gamer how often they've heard of someone getting compromised.

The simple truth of this is, no matter how good the hardware platform is, how good the process is from the service provider, & how good you think your staff is, the real threat to the security of your business comes from within. Your service provider is only as good as your own instructions, your own knowledge & understanding, & your own ideals, & those ideals being kept rigidly.

A degree of suspiciousness, caution & paranoia is not only healthy, but acceptable as well as needed in today's Digital Age. The level of concern about security in the cloud is really to do with business' own insecurity over its own processes, data handling ideals than what the service provider's level of security offers. If you can sleep well at night knowing your wallet is safe, shouldn’t your data in your business be able to feel the same?

Monday, November 14, 2011

Episode 15: The one where Ireland leaves the front door unlocked

Ireland is at an incredible juncture in its history. Our national debt is of gargantuan proportions, we're in a harsh period of austerity, & the real economy is on the verge of complete collapse with barely any growth, & things are looking to only get worse for the citizens. Our exports however are the only thing that's saving our bacon. Richard Bruton, the Minister for Jobs, Enterprise & Innovation stated last month in the Dail that "Ireland is well placed to exploit opportunities in new sectors such as Cloud Computing & Digital Gaming, Life Sciences & Clean-tech". He went further to state that "Ireland’s services sector continues to grow & in 2010 accounted for 45.3 per cent of total exports."

One of the growing areas of concern in the tech sector continues to be security. Major gaming hubs from Sony, Nintendo, Enix, Sega Pass, Nintendo & Steam have in recent months come under attack to be compromised, as have Nokia, The Sun, CitiBank to name but a few. When you look through the major gaming names previously mentioned, you realise that these guys are in the top tier of that sector, & with their millions, they got their security totally wrong.

If we're going to engage digital gaming as a means to increase our exports alongside cloud computing, we must place an incredible amount of attention on us having a strategy for cyber security in Ireland. In the area of cloud computing, as each market around the world begins the embrace, the first question is always around security, & it continues to be a question even in further developed cloud computing markets.

Ireland is one of the more mature markets for cloud. The sales penetration levels wouldn't tell you that, but it is much further along over four years later from when Ireland's first indigenous cloud computing provider entered the market. Back then, security was a huge issue, & there was alot of scaremongering about the security of the cloud versus traditional managed or collocated I.T. infrastructure services. So, with the market being more mature & over a hundred cloud computing services providers in Ireland, the tech exports market being so crucial to our economy  you'd assume Ireland had a cyber security strategy already in place.

You'd be wrong. According to a question posed by Clare Daly last week to Pat Rabbitte, our Minister for Telecommunications, Energy & National Resources, that framework document doesn't yet even exist. His department are only in the process of developing it for publishing some time in 2012. We're hedging our survival as a country on I.T. services, & the digital economy & we have absolutely no framework as a country on the single biggest threat & concern to that sector?

Coincidentally, my collegue over at CloudBook, Thu Pham, wrote a great article about the concerns of security in the Cloud for SMB's (or, SME's to us in Ireland). While this article does discuss things from a US market standpoint, we're trying to attract US cloud market players to Ireland. So this does provide some viewpoint into what kind of market expectations these players have to work in back home.

Yes, you could revert to type & cast that off as a typically Irish response to a problem, & that it is the same slip-shod approach that was taken to our banking sector; "we'll worry about those problems after the fact." But that's not acceptable. It can't be. If we're spending huge resources on trying to attract direct foreign investment from technology based services companies, positioning Ireland to take advantage of cloud & digital gaming opportunities, this legislation must be of absolute priority.

Four years ago under the previous government, the question was asked about the Irish Governments shift to cloud computing, & the then-Minister for Communications, Eamon Ryan stated that only one department had engaged in looking at a virtualisation or cloud computing strategy so far, & that was his own department. It may be of interest to know that Cloud Computing has been part of Dail discussion 37 times since this present administration has come to power. In seven months, that is approximately five times a month without an exclusion on parliamentary breaks. Thirty seven discussions, with no sign or mention of a government strategy for Cloud Computing to address the costs & inefficiencies of the Government I.T. infrastructure.

There has also been no real approach made to the Cloud Computing industry in Ireland by Government. Discussions behind closed doors with the big five about direct foreign investment don't count. They're not the real players. Had the Government made approaches to companies like Hibernia-Evros, Network Recovery (who recently achieved ISO certification on their cloud), SunGard AS Ireland, DigiWeb, DediServe, DEG-Telecity-Redbus (recent merger of Telecity Redbus & DEG), Eircom, or the any of the other players, any of these players would have made alot of PR hay from the opportunity without any hesitation.

There needs to a proper industry working group, which would help understand the size of the Irish Cloud Computing market, its potential value to the Irish economy from service exports, & its potential for growth, market penetration & adoption throughout the business chain. This group needs to work with the department of trade, the department for public finance & expenditure, as well as the department of communications to help it understand what is needed from a national cyber strategy.

Ireland asked & got its change of leadership earlier this year, it is now time that changed leadership acted like leaders, instead of dithering like a deer in the headlights, reach out to  those in the Irish Cloud market, reach out to those in the Digital arts markets (gaming/entertainment etc.), form some proper advisory working groups, & get on with helping to make the push behind a group of industries that form the tech sector that helps support our exports to allow us to fix our real economy, or are they going to continue to bet the farm on those who will move at a moments notice for tax & cost sakes premiums?

Monday, July 4, 2011

Episode 10: Band On The Run?

People think Cloud is big business now. We're not even at the projected years yet like 2014 where some have estimated it will be worth as much as USD$150bn. There is a growing perception out there amongst executives in business that 'Cloud' is nothing more than a really nice way of saying 'outsourcing' & question its value based off that, which is really the wrong way to view it. But leaving that aside, the other side of the table are the Cloud service providers.

So far in the Cloudiverse, we've:
  • SAAS - Software As A Service
  • PAAS - Platform As A Service
  • IAAS - Infrastructure As A Service
  • CAAS - Cloud As A Service (granted this is my own term - but still!)
Last week upon my weary travels through the countless number of articles/blogs/opinions/reports I read every day a new term came creeping like a truck hurtling down a mountainside into my view;

Desktop As A Service, or DAAS.

That's right, 'DAAS'. In the late 90's there was a running joke amongst I.T. workers about TLA's (Three Letter Acronymns) & even some went as far as XTLA's (Extended Three Letter Acronymns, which was another humourous way of saying four letter acronymns). In my early days as a support engineer we would try find as many funny TLA's or XTLA's as we could for things during mind-numbing tasks as a way of lightening the mood. A collegue of mine one day introduced me to the term 'PEBKAC error' (Problem Exists Between Keyboard And Chair). Even to this day it brings a wry smile to my face.

But it does over a decade later have me asking, are we getting to the stage again where in order to 'sound' convincing we're confusing the end user with loads of fancy abbreviated terminology? It is bad enough that currently there are so many people out there who from a lay person's stand-point can see how some of these 'Cloud services' can help their businesses. Whether that's to save money, or divesting themselves of capital investment, or just making access to certain systems more global or location neutral. There is a growing problem where despite the fact Cloud companies are sprouting up at the rate Dot Com businsses used to, the market is not being brought along for the ride with it.

There is a sales technique called 'the band wagon effect' where in a bid to try & have your lead buy in to what you're trying to sell them you tell them that their competitor is using your product/service & already benefitting, so they should to. It is a technique done in the hope of assuading fears about how something may be relevant & useful to your business/vertical, while also inserting another fear; the competition having an edge over you as a business.

I get the feeling in amongst this explosion of cloud that people are really trying to be extreme with the 'first to market' ethos & creating as many new 'As A Service' models as possible in a bid to hitch their own wagons to the Cloud band wagon. While no-one can ever deny the fact it's easier than ever to establish a solutions based business to leverage off the Internet, & tag your solution as a 'Cloud' service, there's a temptation for the I.T. industry to 'pig out' on what alot must feel is an 'all you can eat buffet' in the Cloud.

They say unless you learn from history, you are doomed to repeat it. The last time there was a feeding frenzy like this it was called the 'Dot Com Bubble', & that burst. Hard. It also took alot of investors with it & alot of VC companies took a real kicking, especially over companies like 'Boo.com'. Yes, you shouold make hay while the sun shines, but considering the global econmy is still recovering, & here in Ireland we are really struggling, the last thing we need is another over-inflated bubble bursting, which may send any recovery or early signs of it straight into a grave.

As someone whose been involved in the Cloud for some time now, it  has been very good to me in terms of employment, work, & opportunity. Not to mention the education it has given as well as enthusiasm again for the I.T. service industry. While we all as Cloud warriors, defenders, enthusiasts, developers, founders, evangelists, champions, consultants etc. want to share this with the world, make some bucks too (because this is what it is ultimately about), we must ensure that as chiefs in our tribes bring the tribes along with us, otherwise we're going to be standing there all on our own looking at a very expensive totem pole that everyone else stopped  caring about, & sees no relevance in, with a very hefty tab awaiting us, wondering why people 'don't understand' or 'don't get it'.

Tuesday, June 28, 2011

Episode 8: A guy walks into a bar & orders a beer with his Cloud

I recently had the pleasure of attending a talk given by Go-Oodles at one of the Google offices in Dublin, where I was also introduced to the Chromebook, which is due to hit our shores in July through the guys at Go Oodles. The Chromebook is Google's chosen fighter to enter the ring against Apple's leviathan iPad, which has decimated the competition in the tablet market after initially being scorned by some upon its introduction, & sold like crazy, where you can't even get one in a PC World outlet unless you're there on a Tuesday morning when they get their fresh deliveries of them!

Some have asked why Google are even going down this road considering the spectacular problems facing their Android platform. The issues facing Android are in fact absolutely no fault of Google's, but the poor exposition of Android by handset makers, carriers & what those aforementioned pair have done with their own respective implementations of Android, & also that there's less choice in the way of Apps as a result, as application developers make more money per App from iOS apps than Android ones.

Even in my own experience with my own Android tablet, saw me unable to load a great deal many applications from the official Android Market, because the applications were meant for Android Phones, not tablets. In fact, I'm pretty sure I've actually never used a full unmolested version of Android from Google. Yet I know when I pick up an iOS device; I can have any flavour I want, as long as it's Apple.

But, I'll digress at this point about that as this is not a blog about tablet computing, or Android VS iOS, but how tablet computing is in fact going to lead the march into the cloud, lemming style. While the enterprise is slowly moving into the Cloud, the consumer market is there, front & centre, & the push is persistent, kept simple & enabled by peple like Google, Microsoft, Apple, & Amazon.

Each of these players is involved with some consumer hardware that pushes people with ease into the Cloud & the use of cloud services. I pick up an iPad now, I no longer need a computer to activate it, & I can get straight into the iTunes Cloud to consume as much or as little as I like, & then shove what I want back up into iCloud.

I open up a Chromebook, find a wifi connection, I can work in Google Docs, check my Gmail, & listen to my music up in Amazon's Sound Drive, even watch videos out of YouTube. I can lose my Chromebook, or it break, I can contact Google, or a designated Google partner, & I'm right back there, no data lost, no more 'ah crap, I forgot to back X or Y up!'

Budweiser recently introduced an iPhone app that will track then temperature near where I am & give me cut-price beer in a local bar, or a free drink should it reach a certain temperature. The Cloud is bringing me cheap, or free beer. WOW!  If you stood up at a Cloud Computing conference, or talk & made the statement of 'Cloud can even bring free beer to the masses' you would not only be laughed at, but questioned as to whether you yourself perhaps had too much beer.

Within every 'Cloud' company right now there is a drive to push adoption & sales like crazy. Executives are demanding numbers. Sales guys are hitting the market hard & aggressively. In some cases, the numbers are coming up short. Routes to market are being reviewed, messages being tweaked, even the offerings are getting changed, or re-imagined for re-marketing.

The successes in enterprise cloud right now are coming hard & fast in areas of software as a service, like e-mail, officeware or CRM's. These are the real fast quick wins for business consumer and service provider. Large complex migrations are never going to shorten down into exec-friendly boardroom pleasing sales cycles.

People are looking at companies like Google, SalesForce, Marketo, Microsoft Azure, Amazon, Apple & wondering why their Cloud offerings are not beating the paths to revenue like these guys are. These guys defined cloud. They were not only born from it, but pretty much defined it respectively. They fulfill the basic needs immediately, don't require much action in terms of market persuasion for people to beat a path to their door, & allow easy, non-fussy consumption of their services.

When you think of them you don't think 'Cloud service'. You don't find yourself asking 'okay, how does their cloud work'. 'How do I benefit from them?' You don't even find yourself really having to do much thinking at all to be on their cloud. And yet each of these guys despite being very active in the enterprise market, is exponentially more active in the average joe's life.

Countless droves of your every-man or every-woman has a G-mail or Hotmail account. Hundreds of millions of us have Apple iPods, or iPhones, or iPads (indications are a huge number have one or more of these devices or even all three!). Alot of us have bought products via Amazon's store, & alot of use SalesForce at our work. And as for Google, a billion unique visits per month across their services says it all.

Amazon are even in the process of introducing their own low-cost tablet computer, which some  seem to think will deliberately be sold at or below cost so they can storm into the market & east into Apple's share, & grab those who are still unconvinced by Apple's pricing. This tablet is also believed to also tie neatly into Amazon's AppStore, Cloud Drive & own online store with ease. Further making the push into cloud via consumer devices.

Thursday, June 16, 2011

Episode 7: Hello cloud, I'm a business - who are you?

Over sixty percent of Irish businesses cited the cost savings as an imperative for cloud adoption in Ireland according to a very recent survey commissioned for Cloud Arena by Seefin Data Management. Now while that may be pretty much par for the course & pretty much part of the standard message of Cloud Computing, others findings from this survey for most Irish cloud companies are of greater concern.

"The biggest challenge is that we need to learn more about Cloud & how it works"

"Inertia & a fear we need to be technically expert"

"Limited knowledge of cloud systems"

These were some of the comments that came back as part of the survey, accompanied by the statistic that over 20% of respondents said that overall understanding of the Cloud within their companies was low & they felt there was a need to educate their staff about the effectiveness of the Cloud. Cloud right now is THE buzzword in I.T., & Irish companies appear to be grasping it quite well when it comes to calling their products 'Cloud', but many of them seem to be very poor at actually using it to present better levels of infrastructural & I.S. cost economics to their business.

The comments about education are in some-ways almost a catch-22. For alot of these companies, if you were to suggest to them that to better educate their staff on the benefits/effectiveness that some form of training needed to be invested in, red flags would appear & a look of panic would befall the CFO in the business. There is also the flip side that in some of these companies that they continue to used aged technology because 'it's what they know', & no matter how great a new piece of tech might be for the business, there may be that I.T. manager who will find a way to shoot it down because it means he/she has to re-train, re-learn new things.

There is a perception that people who work in I.T. always want to learn the newest technologies, always keen to be dynamic, motivated to get to 'play' with new things. This is not always the case. People who work at the cutting edge will always remain there. People who work with older technology, from my own experience have generally tended to stay there, age with the tech they oversee & go through the motions to pick up the paycheck.

Another issue with the cloud is the absolute muddy-ness of the term itself. For companies who are trying to understand how they can harness the cost savings Cloud purports, tell them there's IAAS, PAAS & SAAS & their heads auto-explode instantly. This also is in line with the comments from the Cloud Arena survey of "Inertia & a fear we need to be technically expert".

The muddy-ness doesn;t end there. There's companies who are engaging in re branding services as 'Cloud' for a cash-in, who won't be challenged on it by their industry peers. The entire idea of Cloud following the spectacular collapse of the global economy has helped increase the buy & sell opportunities for cloud off the back of 'cloud saves you money' will not be placed in jeopardy by any kind of internal squabbles in the industry over whose products/services are/are not Cloud, or the industry self-examining. There are some minor indications of this where you'll often see some IAAS providers use statements like 'we are true cloud', but won't then follow-up by saying what is 'not cloud'.

How is any of this supposed to help get those who want to actually help their businesses engage in some obvious wins for their business in terms of costs, redundancy gains, & provider diversity to secure their business futures? It doesn't. All it does is prolong the sales cycles for cloud service providers, leave  the issues facing buyers completely unaddressed & ultimately see the industry around the Cloud self-sabotage the opportunities. If you want passengers on your ship, you need to give them clear reasons to come aboard & stay - the idea of 'saves you money' or 'a great deal' is not enough anymore. There has to be an absolutely crystal clear value proposition that is plain as day, as money & credit even more so, is hard to come by these days. Pennies are being watched like they are large denomination notes.

Clarity & transparency about the cloud in the way the bottom part of the cloud food chain needs it to be to give full end-to-end adaptation, & growth I fear will be procrastinated upon the same way migration to IPV6 has been done. I remember discussing about migration & implementation of IPV6 over 6 years ago with some acquaintances of mine who were senior network engineers, & in recent conversations with them, they said they still hadn't moved into IPV6 because there was an argument about cost & the benefits still going on despite the imminent day zero scenario approaching.

Right now, as much as Cloud is the meal ticket for the technology industry, & those who leverage off it heavily to in turn provide services/businesses using it, even the lack of interoperability between various cloud systems/services/products is something that the industry itself won't address because there is too much at stake. It is pretty much an unspoken state of 'hold-fire' that in the near future will come to a crunch-time the same way IPV4 has. All this does is continue to leave the Cloud as an aspiration that people who want it will never reach, much like the white fluffy counterparts in the sky.

Wednesday, May 4, 2011

Episode 5: Cloudy with a chance for goofballs & legal headaches.

Cloud. Security. Two words consumers of the cloud want together, side by side. Hand in hand. In the early days of the cloud, it was the easiest card to pull to deter people from moving to the cloud. To some degree, it's less of an issue with the normalisation of 'cloud' (or is that rebranding of existing systems as cloud, another debate for another day) into every-day Internet services such as Google GMail, Apple iTunes, SalesForce, MSN Hotmail, & the countless other software-as-a-service or platform-as-a-service interactions we consume online.


And yet, a study released last week by the Ponemon Institute in conjunction with CA Technologies shows that in Europe 35% of I.T. professionals strongly agreed or agreed that I.T. leaders in their organisations are concerned about the security of cloud computing resources that is provided to their customers. That is utterly incredible. Not to mention utterly irresponsible. In the U.S. this figure was even lower at 23%. (To see a breakdown on the sampling, click here).


Even on the face of this set of statistics alone, in Europe a little over a third of people tasked with setting the I.T. agenda in businesses that deploy cloud services care about the security of use to be extended to their own customers. Some people when presented with this would be horrified & retreat further from ever going near the cloud. 


What is scarier again is that in Europe, approx. 46% of cloud service providers think that security is important when it comes to their operations & how they handle data, & the study went further to then suppose that security is not part of the reason people use their cloud services.


So, almost half the cloud providers in Europe have a complete disregard for the security of your personal data & assume because as a customer you don't state it up front, & the biggest reason to move to the cloud for people is to reduce cost, it's something they should disregard. Now, there's a train of thought (and legally bound via the Data Protection Act) here that says that as the owner of a business, you are ultimately responsible for the security of your customer information; i.e. credit cards, customer details etc.. This goes for the customer using Cloud services to enable their business, & also the cloud service provider.


Want the truly scary statistics? In a combined result of U.S. & European cloud providers just 37% responded they were either confident or very confident they could identify & authenticate users before granting access to services/data/systems, while 81% of that same sample said they were also confident or very confident they provided access to highly qualified I.T. security personnel.


81% said they can provide access to highly qualified I.T. personnel, yet those same people are only 37% confident in an absolute fundamental of security, leaving I.T. aside - access control; making sure the right people are able to access a resource & keeping the wrong people out. That is not only mind-blowing, but nothing short of disgraceful. Whatever about maintaining up-time, or performance, controlling access to the data of god knows how many people's personal information should at all times be paramount to absolutely everything else. There should be NOTHING more important than rigid controls on that aspect. Losing people's personal data through poor access control is the equivalent to leaving your house unlocked or unsecured.


I could go into further shocking details or summaries from the report, but I've linked it earlier in the article, & will close instead on the real crux of what I'm trying to get at here with these revelations.


You start an Internet business. It's great because you can keep costs down unlike a traditional bricks & mortar business. You can get up & running fast, & buy 'expertise' to do so relatively cheap & from around the world. And that's great, but there's one absolutely fundamental question you should always ask yourself;


"If this was a business on the high street, what considerations would I be giving to security, insurance & risk?"


The recent breaches with Sony should bear enough testament to how much furore, unwanted media attention & pending legal action in the U.S. & Europe they have brought down upon themselves over the breaches of approx. 77 million PSN users. Sony is also being investigated in Ireland by the Data Protection Commissioner over the incidents that affected Irish PSN users. Lets us not forgot the incidents in Ireland in recent times, two high-profile ones being the Irish Blood Transfusion Services, & Bord Gais  .


Data protection breaches are bad for business, & will earn you as a business a very uncomfortable conversation with the Data Protection Commissioner of Ireland, who in recent years following high profile incidents has taken a shine to dispensing costly fines to businesses. A good blog post by ICS IT Law was written a little over  a year ago on this topic, which provides a compelling further exploration on this topic. If as a business you are unsure about data protection, or the levels of data protection exercised by your cloud service provider, please read the information at this link from the Irish Data Protection Commisioner.

Friday, April 22, 2011

Episode 4: The Day The Cloud Crashed & People Lost Their Minds

February 20th 2011 will be a date that cloud commentators, cloud zealots & the opportunists in the cloud will make sure is not forgotten. Amazon AWS had a colossal outage. This article from the BBC exemplifies the kind of coverage that went along with the event. Needless to say, alot of people directly affected as customers of AWS were miffed, as were users of those services hosted there in the affected area. And no, SkyNet did not begin its take-over starting with AWS for those who were concerned.

First off, one thing really needs clarifying about this event, as the reaction in social media circles, especially amongst twitterati was grossly out of of proportion. The reality of this is that a SINGLE region in Amazon's network was down. The rest of their services in the USA were fine, as were their European & their Asian services. The fact that the affected region services so many companies made the issue seem far greater than it was. Amazon AWS customers who engaged in deploying their cloud strategy across multiple regions in Amazon's EC2 system were completely unaffected.

The fact it went on for over ten hours yes is a concern. And rightfully so. But, did it violate Amazon AWS's 99.95% SLA which allows for '4 hours per year of downtime'? Nope. Not even in the slightest, even with their 10 hours of being unavailable to people who were screaming over lack of access to key services. But, screaming doesn't get around SLA's you agree to for services you take, or use. Always check the warranty.

And this is the real thing to remember; the fine print of your SLA's or terms & conditions of service are the last word in any comeback you have. Cloud Providers trying to win business from AWS to their own services around the world, especially in Ireland cried foul. What they neglected to tell those same Irish companies they were trying to win business from as a result of the outage was that their own SLA's & guarantees are in fact absolutely no better than Amazon's ones. In fact, some of them have in their terms & conditions that you have absolutely no comeback whatsoever in the event of an outage, & there are no guarantees on up-time at all, even at centre power/connectivity level, which some at least provide.

The companies who promote their uptime & their 'solid SLAs' if you dig into them are actually nothing more than guarantees against power & network connectivity to an actual hosting center itself, & unless both those fail for more than four hours in a year, you could lose access to your VPS or cloud for days on end due to a hardware, or virtualisation or internal networking issue & they would still not have violated their SLA with you.

Beware of service providers who are eager to bash the performance of their competitors openly. They'll mouth off quite happily about others lack of 'service', while at the same time not being so mouthy about what happens when (not a case of 'if' with technology, but 'when') their services fail on you. And believe me they will. If multi-billion dollar global companies like Amazon, Google, Microsoft, Apple & others have outages, your local provider who is less equipped staff-wise, financially & technically to be as able to deal with outages as efficiently as those corporations who have vast resources in all areas. It is also important to remember a very old adage when it comes to this, empty vessels make the most noise.

So, you're a company looking to engage a cloud strategy because you can see the benefits, but are scared by what happened with Amazon AWS from what you read on blogs & Twitter. You don't know what to do next. Firstly, the most important thing to do is ignore Twitter & the blogs decrying AWS. These are but a noisy few out of millions. Many of them are vested interests & vested interests should be ignored like the plague.

A good cloud service provider will be upfront with you when you engage them. They should be knowledgable enough to work with you in understanding your requirements, explain what risks there are to what you want to achieve, & provide advice on how to mitigate against the risks to what you want to do. Sure they're there to sell you services & gain your custom, but a good consultant will tell you that they are & should only be part of a solution to you. That as good as the company they represent may be, risk should always be spread.

Every company involved in risk management as a business will tell you that the absolute fundamental to risk management is spreading that risk around in a controlled manner to shore up your mitigation. Mitigating risk is not cheap. So don't fall for companies promising you to be the 'cheapest solution for your business' - they're not. They are if anything given their pricing, a small part of a solution to you. You also need to ensure that you have a communications plan in place in the event of any outages, as well as documented & tested internal procedures on how your teams & staff need to act, & what events need to be triggered if any to mitigate the circumstances or ease them as much as possible.

But this issue goes outside your cloud provider. It comes down to your choice in developer also. Your developer if they are worth their salt should have an application that allows for spread, that allows for redundancy. They should also be advising you to spread your system across at least two providers or two centers at the very least if your single provider can actually do this. Your cloud provider really should even do this. Single cloud services are single points of failure.

And the issue of disaster recovery or planning doesn't even stop at the developer or the service provider. You, as the business owner/operator leading your organisation are the absolute linchpin of it all. Fundamentally, being a good leader means being a good planner. As a leader of yours, it is incumbent upon you to plan, & plan well & properly.

'The Cloud' is not a solution to redundancy, or disaster recovery. It is a tool to help mitigate some aspects of risk at best in a cost effective manner for its part. It should never be the case of "Oh, it's in the cloud, no need to worry or care. It's taken care of already by my cloud provider." Just because it's easy to set up a business in the internet space, doesn't mean normal conventions for business disaster recovery, or 'battle-stations' planning doesn't apply. The fundamentals of good business planning apply to the Internet as much as the high-street. Most of the time, it's just cheaper. Shortcuts on these areas are just that, except to one day being caught proverbially with your pants around your ankles.

Remember; a blip in the operation of your business from an outage won't kill your business, but how you manage that blip, communicate & work towards the point of restoration will determine whether your business will recover when it happens. Another couple of adages worth closing this blogpost with is 'plan for the worst, hope for the best', 'expect the unexpected' & 'if you want peace, prepare for war'.