Skip to main content

Cloud Technology and Security Alert News Digest – Issue #15

Update 2019: We’ve been busy working on some great training content around security, check out the Cloud Academy library to prepare on all-things cloud security.


Privacy and Security in the Cloud

Welcome to the Cloud Technology and Security Alert News Digest. This week we’ll discuss the problem of Internet security along with three possible solutions: a new open certificate authority, premium access, and creating an ultra-private internet of your own. We’ll also take a look at the new trend towards Docker orchestration.

Which Internet do you use?

ZDNet has an interesting article about the many ways that the Internet you experience, to a very large degree, depends on our economic and political class. Lenovo’s recent revelation that they only installed Superfish on “consumer” devices – leaving the browsers of their enterprise customer devices under end-user control – is one more indication that enterprise users enjoy a “premium” Internet. In addition, out of mistrust of the activities of US government spy agencies like the NSA, many nations are now encouraging their technology providers to avoid routing regional online traffic through the US, creating still more variations in online experience.

WordPress plugin vulnerability

Ars Technica (among other sources) reports the existence of a critical vulnerability in the Slimstat 3.9.6 WordPress plugin. This version of Slimstat, which is a very widely used analytics tool, is susceptible to blind SQL injection attacks and should be disabled immediately.

The next big Docker thing: orchestration

ZDNet reports that Docker is successfully moving its container orchestration tools through their beta stage. Docker Machine (which allows you to manage containers spread across multiple platforms and technologies), Docker Swarm (a clustering service), and Docker Compose (a tool for marshaling containers playing disparate roles in a distributed app infrastructure) are the key components of this orchestration initiative. Eventually, Docker plans to fully integrate these tools into Amazon EC2, Microsoft Azure, and other cloud platforms.

If you build a better certificate, will they come?

David Holmes at Security Week writes about a proposed initiative designed to provide a practical alternative to inherently weak self-signed SSL certificates. The existence of such weak certificates lies behind many web vulnerabilities, including Lenovo’s recent SuperFish disaster. The Electronic Frontier Foundation (EFF) has proposed a new open Certificate Authority, called Let’s Encrypt, that will make it simpler and more affordable for smaller web providers to deploy secure services. Holmes, while supportive of the effort, suspects that most of the sites that need it most will probably ignore Let’s Encrypt.

Amazon’s CIA cloud goes operational

Amazon’s AWS has long offered specially secured arrangements for sensitive customers like the US government (GovCloud) and China. Now, according to Cloud Computing News, they’ve moved to a new level entirely. Having won the competition to provide private cloud services to the CIA, AWS has now achieved “final operational capability” and can begin supporting communications between seventeen US intelligence agencies.

Written by

David Clinton

A Linux system administrator with twenty years' experience as a high school teacher, David has been around the industry long enough to have witnessed decades of technology trend predictions; most of them turning out to be dead wrong.

Related Posts

Guy Hummel
— March 4, 2019

What is Ansible?

What is Ansible? Ansible is an open-source IT automation engine, which can remove drudgery from your work life, and will also dramatically improve the scalability, consistency, and reliability of your IT environment. We'll start to explore how to automate repetitive system administratio...

Read more
  • Ansible
  • Cloud Computing
Cloud Academy Team
— February 11, 2019

What is Puppet? Get Started With Our Course

When it comes to building and configuring IT infrastructure, especially across dozens or even thousands of servers, developers need tools that automate and streamline this process. Enter Puppet, one of the leading DevOps tools for automating delivery and operation of software no matter ...

Read more
  • Cloud Computing
  • Puppet
Andrew Larkin
— January 15, 2019

2018 Was a Big Year for Content at Cloud Academy

As Head of Content at Cloud Academy I work closely with our customers and my domain leads to prioritize quarterly content plans that will achieve the best outcomes for our customers.We started 2018 with two content objectives: To show customer teams how to use Cloud Services to solv...

Read more
  • Amazon Web Services
  • Cloud Computing
  • Google Cloud Platform
  • microsoft azure
Cloud Academy Team
— December 21, 2018

2019 Cloud Computing Predictions

2018 was a banner year in cloud computing, with Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP) all continuing to launch new and innovative services. We also saw growth among enterprises in the adoption of methodologies supporting the move toward cloud-native...

Read more
  • 2019 Predictions
  • Cloud Computing
Albert Qian
Albert Qian
— August 28, 2018

Introducing Assessment Cycles

Today, cloud technology platforms and best practices around them move faster than ever, resulting in a paradigm shift for how organizations onboard and train their employees. While assessing employee skills on an annual basis might have sufficed a decade ago, the reality is that organiz...

Read more
  • Cloud Computing
  • Product Feature
  • Skill Profiles
Stefano Bellasio
— July 31, 2018

Cloud Skills: Transforming Your Teams with Technology and Data

How building Cloud Academy helped us understand the challenges of transforming large teams, and how data and planning can help with your cloud transformation.When we started Cloud Academy a few years ago, our founding team knew that cloud was going to be a revolution for the IT indu...

Read more
  • Cloud Computing
  • Skill Profiles
Andrew Larkin
— June 26, 2018

Disadvantages of Cloud Computing

If you want to deliver digital services of any kind, you’ll need to compute resources including CPU, memory, storage, and network connectivity. Which resources you choose for your delivery, cloud-based or local, is up to you. But you’ll definitely want to do your homework first. In this...

Read more
  • AWS
  • Azure
  • Cloud Computing
  • Google Cloud
Albert Qian
Albert Qian
— May 23, 2018

Announcing Skill Profiles Beta

Now that you’ve decided to invest in the cloud, one of your chief concerns might be maximizing your investment. With little time to align resources with your vision, how do you objectively know the capabilities of your teams?By partnering with hundreds of enterprise organizations, we’...

Read more
  • Cloud Computing
  • Product Feature
  • Skill Profiles
Cloud Academy Team
— April 5, 2018

A New Paradigm for Cloud Training is Needed (and Other Insights We Can Democratize)

It’s no secret that cloud, its supporting technologies, and the capabilities it unlocks is disrupting IT. Whether you’re cloud-first, multi-cloud, or migrating workload by workload, every step up the ever-changing cloud capability curve depends on your people, your technology, and your ...

Read more
  • Cloud Computing
Tyler Stearns
— March 29, 2018

What is Chaos Engineering? Failure Becomes Reliability

In the IT world, failure is inevitable. A server might go down, an app may fail, etc. Does your team know what to do during a major outage? Do you know what instances may cause a larger systems failure? Chaos engineering, or chaos as a service, will help you fail responsibly.It almo...

Read more
  • Cloud Computing
  • DevOps
Cloud Academy Team
— November 22, 2017

AWS re:Invent 2017: Themes and Tools Shaping Cloud Computing in 2018

As the sixth annual re:Invent approaches, it’s a good time to look back at how the industry has progressed over the past year. How have last year’s trends held up, and what new trends are on the horizon? Where is AWS investing with its products and services? How are enterprises respondi...

Read more
  • AWS
  • Cloud Adoption
  • Cloud Computing
  • reInvent17
Cloud Academy Team
— October 27, 2017

Cloud Academy at Cloud Expo Santa Clara, Oct 31 – Nov 2

71% of IT decision-makers believe that a lack of cloud expertise in their organizations has resulted in lost revenue.1 That’s why building a culture of cloud—and the common language and skills to support cloud-first—is so important for companies who want to stay ahead of the transfo...

Read more
  • Cloud Computing
  • Events