German researchers have found flaws in Amazon Web Services that they think may exist in many cloud architectures and give hackers access to administrative rights and thus, access to all user data. The workaround involves XML modification to create new instances of the customers cloud, and then giving access to add or delete items within the cloud. "It's not only a problem of Amazon's," says Juraj Somorovsky, one of the researchers. "These are general attacks. Public clouds are not so secure as they seem to be. These problems could be found in other cloud frameworks also."
If these vulnerabilities are present in many of today's cloud, then the distributed computing and cloud storage in general could represent a large security risk for large companies looking to adopt this form of distributed computing systems. If the basic security could be handled by local physical hardware then it would possible to secure these systems enough for them to be widely propagated as a primary storage and computing medium.
http://www.computerworld.com/s/article/9221212/Researchers_find_massive_security_flaws_in_cloud_architectures?taxonomyId=158

No comments:
Post a Comment