成人小说亚洲一区二区三区,亚洲国产精品一区二区三区,国产精品成人精品久久久,久久综合一区二区三区,精品无码av一区二区,国产一级a毛一级a看免费视频,欧洲uv免费在线区一二区,亚洲国产欧美中日韩成人综合视频,国产熟女一区二区三区五月婷小说,亚洲一区波多野结衣在线

立即打開
第一資本數(shù)據(jù)泄露,大企業(yè)該擔(dān)心公共云嗎?

第一資本數(shù)據(jù)泄露,大企業(yè)該擔(dān)心公共云嗎?

Robert Hackett 2019-09-04
一名黑客利用“配置錯誤的防火墻”攻破了第一資本的系統(tǒng),基本上就相當(dāng)于小偷從敞開的門溜進去。

圖片來源:Smartstock/Getty Images

很難找到比第一資本更積極使用所謂“公共云”的公司。按營收計算,第一資本排名美國第七大銀行,多年來一直在逐步縮減其數(shù)據(jù)中心,利用亞馬遜網(wǎng)絡(luò)服務(wù)隨時可用的資源計算和存儲數(shù)據(jù)。2014年第一資本有八個數(shù)據(jù)中心,計劃到2020年底縮減到一個也不剩。但在影響到1.06億北美人的數(shù)據(jù)泄露事件發(fā)生以后,人們開始質(zhì)疑第一資本的故事是否在警示網(wǎng)絡(luò)安全。

據(jù)說,一名黑客利用“配置錯誤的防火墻”攻破了第一資本的系統(tǒng),基本上就相當(dāng)于小偷從敞開的門溜進去。第一資本和亞馬遜都強調(diào)稱:“此類漏洞不只云技術(shù)才有?!?/p>

但是,初創(chuàng)公司Cloudflare的安全經(jīng)理埃文·約翰遜等專家表示,亞馬遜網(wǎng)絡(luò)服務(wù)的技術(shù)設(shè)置導(dǎo)致黑客入侵的后果“嚴(yán)重得多”。約翰遜稱,亞馬遜網(wǎng)絡(luò)服務(wù)特別容易受到“服務(wù)器端虛假請求”的影響,即黑客欺騙服務(wù)器接受錯誤連接,從而實現(xiàn)數(shù)據(jù)竊取。應(yīng)該采取更好的風(fēng)險減輕措施,他說道。

盡管第一資本的因數(shù)據(jù)泄露案而備受批評,但這“并不能夠證明應(yīng)用云技術(shù)有錯”,技術(shù)和市場研究公司Forrester的副總裁格倫·奧唐奈說道,“該案例證明的是,從安全和治理的角度來看,必須采取正確的控制措施。”

AT&T的前首席安全官埃德·阿莫羅索也認(rèn)為,對于大多數(shù)企業(yè)而言,與其自行管理基礎(chǔ)設(shè)施,還是全盤轉(zhuǎn)向云服務(wù)更加安全:“不能苛求‘完美’,要跟‘自行管理’的成本比較?!保ㄘ敻恢形木W(wǎng))

本文另一版本登載于《財富》雜志2019年9月刊,標(biāo)題是《第一資本遭到攻擊》。

譯者:艾倫

審校:夏林

You’d be hard-pressed to find a company more committed to using the so-called public cloud than Capital One. America’s seventh-?biggest bank by revenue has spent years winding down its data centers—from eight in 2014 to zero planned by the end of 2020—and relying on the on-tap resources of Amazon Web Services for computing and data storage. But now, in the wake of a data breach affecting 106 million North Americans, people are questioning whether Capital One represents a cybersecurity cautionary tale.

To burrow inside Capital One’s systems, a hacker supposedly exploited a “misconfigured firewall.” Basically, the thief snuck in an open door. Both Capital One and Amazon stressed that “this type of vulnerability is not specific to the cloud.”

Yet some ?experts, such as Evan Johnson, a security manager at startup Cloudflare, say AWS’s technical setup made the breach “much worse.” AWS is particularly susceptible to “server side request forgery,” Johnson says, in which a hacker tricks a server into connecting where it shouldn’t, enabling data theft. Better mitigations ought to be in place, he says.

Despite the criticism, Capital One’s breach “doesn’t prove the cloud is wrong,” says Glenn O’Donnell, a Forrester VP. “What it does prove is you have to have the right controls in place from a security and governance perspective.”

Ed Amoroso, ex–chief security officer for AT&T, agrees that for most businesses, off-loading infrastructure to the cloud remains safer than managing one’s own: “You have to compare not against ‘perfect’ but against ‘on premises.’”

A version of this article appears in the September 2019 issue of Fortune with the headline “Capital Offense.”

掃描二維碼下載財富APP
亚洲欧美日韩中文在线制服日本免费一区香蕉视频| 免费午夜无码片在线观看影院| 国产精品美女久久久m| 亚洲v国产v天堂a无码二区久久| 国产一级一级理论片A片一区二区| 亚洲6080yy久久无码中文| 亚洲精品午夜久久aaa级久久久| a级午夜毛片免费一区二区| 亚洲av日韩av天堂一区二区三区| 欧美成人无码禁片在线观看| 精品国产AⅤ一区二区三区4区| 美女哺乳久久精品免费视频| 亚洲AV成人无码精品网站漫画| 純愛無遮擋H肉動漫在線播放| 97国产在线看片免费人成视频| 最近中文字幕MV在线视频WWW| 欧洲变态另类zozo-av色国产色拍| 欧美久久久久久久久中文字幕| 色综合a在线中文字幕| 日韩精品爆乳高清在线观看视频| 久久久久亚洲AV成人无码| 国产精品高潮呻吟久久AV无码| 国产亚洲综合91精品| 亚洲成AV人片在线观看无| 国产强伦姧在线观看无码| 77777亚洲午夜久久多人| 日韩人妻无码肉v视频| 国产精品视频白浆免费视频| 久久国产劲爆AV内射—百度| 久久婷婷五月综合丁香人人爽| 中文字幕乱码人妻无码久久免费| 年经丰满岳欲乱中文字幕| 精品2021露脸国产偷人在视频| 国产精品乱码高清在线观看| 国产精品国产精品国产专区不卡| 乱肉艳妇熟女 岳| 番里H肉3D动漫在线观看| 亚洲中文字幕国产综合| 亚洲亚洲人成综合网站| 办公室撕开奶罩吮奶在线观看| 久久免费精品一区二区|