Welcome!

@CloudExpo Authors: Elizabeth White, Liz McMillan, Pat Romanski, Roger Strukhoff, Don MacVittie

Related Topics: Server Monitoring, @CloudExpo

Server Monitoring: Article

Data Danger Lurking in Public Cloud Contracts

Providers Protect Themselves - Your Data, Not So Much

Last month, in an article titled, Tiny Company Solves Giant Problem in Cloud-Based Document Management, I wrote about CloudPointe and their unique approach to addressing the perils of cloud-based document management.  I looked at how nearly all cloud services that handle documents, media files, and other forms of data suffer from a common weakness:  they force customers to entrust their data assets to the cloud service provider and in so doing take on several big, largely unacknowledged risks.

If my article were not enough to draw sufficient attention to this issue, there is an exhaustive new study out that should give enormous pause to organizations considering or already using public cloud services, especially for storing data and documents.  The research was conducted by The Centre for Commercial Law Studies at Queen Mary, University of London and it examines the "Ts&Cs" in the service agreements from a who's who of cloud service providers, from Akamai to Zoho.

The survey covers many different aspects of the agreements, including things like jurisdiction, fair use, arbitration, etc., and it finds many troubling details and patterns that lead the authors to conclude:

"The main lesson to be drawn from the Cloud Legal Project's survey is that customers should review the Terms and Conditions of a Cloud service carefully before signing up to it."

Even after signing cloud services agreements, though, the survey shows that, to be as safe as possible, customers should review them again and again.  In the words of one of the researchers,

"Perhaps the most disconcerting discovery of the Cloud Legal Project's survey was that many Cloud providers claimed to be able to amend their contracts unilaterally, simply by posting an updated version on the web.  In effect, customers are put on notice to download lengthy and complex contracts, on a regular basis, and to compare them against their own copies of earlier versions to look for changes."

Yikes!  That makes those slippery packaged software EULAs from pre-cloud days seem like a blood oath by comparison.

Not surprisingly, the survey devotes the most attention to clauses governing data integrity, preservation, disclosure, and location/transfer, and what it finds there is pretty ugly too.

Data Integrity

After acknowledging the natural customer concerns that data placed in a provider's cloud be kept secure against loss, corruption, theft, and unauthorized disclosure, the research report says,

"Our survey found however that most providers not only avoided giving undertakings in respect of data integrity but actually disclaimed liability for it.

"The majority of providers surveyed expressly include terms in their T&C making it clear that ultimate responsibility for preserving the confidentiality and integrity of the data lies with the customer."

Most of the providers' agreements explicitly counsel customers to encrypt their data and to make separate backup arrangements - even in some cases where the service is backup!

To give credit where it is due, though, in this and a number of the research's other dire findings, Salesforce CRM stands out as a paragon of virtue.  As with only a few other vendors, it's contract acknowledges the company's responsibility in safeguarding customers' data.

Data Preservation

When a company or consumer entrusts its data to a cloud service they should consider provision in the agreement governing what happens to it in the event the contract is terminated.  Can they easily retrieve and transfer the data and will it then be fully deleted from the provider's infrastructure?

The survey shows that most providers fall into one of three categories in this regard.

The providers in one group assert that they will preserve customer data for a set period of time, ranging from 30 days to 3, after the customer terminates their contract.  During this grace period, sometimes for an extra charge, the customer can access and off-load the data and at its end the data will be deleted.

The second group of providers asserts that customer data will be deleted immediately when the agreement is terminated.  Apple's MobileMe service is in this category and its service agreement dryly states,

"Upon termination of your account you lose all access to the Service and any portions thereof, including, but not limited to, your Member Account (any Subaccounts thereunder), Subscriber ID, email account, iDisk, domains, iChat account and MobileMe Gallery albums. In addition, Apple shall delete all information and data stored in or as a part of your account(s) including, but not limited to, data files, email, albums and preferences."

The survey authors rightly point out how this begs the question of what happens in the event that a court later finds that they termination of the contract was ineffective.  They conclude that the service providers in this group may be opening themselves up to civil or criminal liability in some jurisdictions.

Providers in the third group blend conditions found in the first two, acknowledging no obligation to preserve data after a contract has been terminated but also allowing, at their own discretion, an access grace period and/or taking no steps to delete the data at any particular time.

In many cases, though, while providers may not assure that they will keep the data for a grace period or longer, they also do not assure that the data will in fact be deleted, after the grace period or otherwise.

This means that, unless the customer explicitly deletes it after offloading a copy, it may remain in the provider's storage infrastructure for who knows how long.  And, for that matter, given the various kinds of redundancy built into many clouds, even if the customer deletes, it that may not mean that it is really gone.

Data Disclosure

Regarding the potential disclosure of customer data to third parties as in the event of a court order or request from law enforcement officials, the survey found the providers to be all over the place.  They ranged from doing it without notice at their own discretion at one extreme to giving warning or seeking approval at the other.

For example, the now-defunct G.ho.st service stated that it would disclose customer information if it believed that it would protect its own interest by doing so, and the still-in-business ADrive puts it this way:

"You authorize ADrive to disclose any information about You to law enforcement or other government officials as ADrive, in its sole discretion, believes necessary, prudent or appropriate, in connection with an investigation of fraud, intellectual property infringement, or other activity that is illegal or may expose ADrive to legal liability."

At the other extreme is Salesforce CRM, once again taking the high road.  They assure that, unless it is legally prohibited, the customer will be given advance notice of any requested disclosure, and that Saleforce will also assist the customer in opposing such orders.  Now, that's what I call "customer advocacy"!

Data Location / Transfer

Many cloud service providers employ multiple, sometimes numerous data centers in different geographic locations to serve their customers.  This has led to a variety of legal concerns about customers' data being stored or processed in and across potentially unknown or unregulated jurisdictions.

The EU Data Protection regime does provide strong measures to keep cloud-based data within Europe and certain data, like personal information, within specific countries.  But, even in the EU, in-flight data is still at some risk.  And, in the US, where the "long-arm" statutes are considerably looser, and in other places, where there are few or no laws as all to govern where and how data is kept and protected, all bets are off.

So, all in all, concerns about privacy and security in relation to data location and transfer are manifest and important to customers, leading the researchers to observe,

"Perhaps surprisingly, given the prominence often attached to these issues, few of the providers surveyed actually undertake to store data in a particular location or zone. [...]  Indeed, for the 31 sets of T&C reviewed, 15 made no mention of data location or transit protection whatsoever."

The findings of the research concerning data transfer were similar to those for data location.  After acknowledging the international nature of cloud computing and how it means that customer data will usually be transferred between different infrastructure segments over the internet, the report observes,

"Furthermore, if (as many larger Cloud providers do) the provider has multiple data centres, then, unless the provider has built or leased its own secure network and facilities, transfers between data centres may well also be over Internet connections.  Several providers (for example, 37Signals, UKFast) caution in their T&C that customer data may be transferred unencrypted over inherently insecure networks in such a manner."

Losing My Religion

Cloud computing, especially public cloud computing, has many potential benefits but is not without its weaknesses; and, those weaknesses tend to fall into two categories.

There are issues that vendors and customers both readily acknowledge and are working hard to address.  The need for better access security and more management automation fall into this category and will likely be fixed by incremental technical improvements and new products that address them.

Then, there are issues like the subject of this article.  They are ones with little consensus, where most providers are either defiant or in denial, most customers are uninformed or un-empowered, and hardly anybody recognizes that the problem may stem from flawed fundamentals.

Most cloud service providers and most of their customers might find it patent heresy to question the soundness of the idea of putting data and documents into the cloud.  After all, for many that is the very purpose of the cloud, full stop.  If you take back the information assets and put them on a disk array that you own and control, what is left?

There is a lot left, actually.  There is a processing and communications fabric to which most cloud benefits still accrue, and to a greater degree than they do for the comparative commodity of data storage.

The reason the data is in the cloud by default is not because that makes the most sense.  It is because Fibre Channel, Infiniband, and other schemes for directly connecting disks to processors are way faster than those for connecting the nodes of a wide area network.  If that were not true, would everyone still think that the data belongs in the cloud?  I doubt it.

Vendor lock-in, regulatory compliance, privacy, and security are the greatest customer concerns about the public cloud and they are all made considerably worse by the requirement that information assets be placed in the cloud.

CloudPointe already makes a strong case for taking back the documents and files.  WAN connection speeds and the way such information assets are used are both very amenable to sending them through the cloud but not keeping them there.  It may just be a matter of time before improved connection speeds and more advanced distributed database technology allow the same possibilities for other kinds of data.

More Stories By Tim Negris

Tim Negris is SVP, Marketing & Sales at Yottamine Analytics, a pioneering Big Data machine learning software company. He occasionally authors software industry news analysis and insights on Ulitzer.com, is a 25-year technology industry veteran with expertise in software development, database, networking, social media, cloud computing, mobile apps, analytics, and other enabling technologies.

He is recognized for ability to rapidly translate complex technical information and concepts into compelling, actionable knowledge. He is also widely credited with coining the term and co-developing the concept of the “Thin Client” computing model while working for Larry Ellison in the early days of Oracle.

Tim has also held a variety of executive and consulting roles in a numerous start-ups, and several established companies, including Sybase, Oracle, HP, Dell, and IBM. He is a frequent contributor to a number of publications and sites, focusing on technologies and their applications, and has written a number of advanced software applications for social media, video streaming, and music education.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@CloudExpo Stories
In his general session at 21st Cloud Expo, Greg Dumas, Calligo’s Vice President and G.M. of US operations, discussed the new Global Data Protection Regulation and how Calligo can help business stay compliant in digitally globalized world. Greg Dumas is Calligo's Vice President and G.M. of US operations. Calligo is an established service provider that provides an innovative platform for trusted cloud solutions. Calligo’s customers are typically most concerned about GDPR compliance, application p...
"I focus on what we are calling CAST Highlight, which is our SaaS application portfolio analysis tool. It is an extremely lightweight tool that can integrate with pretty much any build process right now," explained Andrew Siegmund, Application Migration Specialist for CAST, in this SYS-CON.tv interview at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
As many know, the first generation of Cloud Management Platform (CMP) solutions were designed for managing virtual infrastructure (IaaS) and traditional applications. But that's no longer enough to satisfy evolving and complex business requirements. In his session at 21st Cloud Expo, Scott Davis, Embotics CTO, explored how next-generation CMPs ensure organizations can manage cloud-native and microservice-based application architectures, while also facilitating agile DevOps methodology. He expla...
SYS-CON Events announced today that Evatronix will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Evatronix SA offers comprehensive solutions in the design and implementation of electronic systems, in CAD / CAM deployment, and also is a designer and manufacturer of advanced 3D scanners for professional applications.
SYS-CON Events announced today that Synametrics Technologies will exhibit at SYS-CON's 22nd International Cloud Expo®, which will take place on June 5-7, 2018, at the Javits Center in New York, NY. Synametrics Technologies is a privately held company based in Plainsboro, New Jersey that has been providing solutions for the developer community since 1997. Based on the success of its initial product offerings such as WinSQL, Xeams, SynaMan and Syncrify, Synametrics continues to create and hone inn...
Cloud Expo | DXWorld Expo have announced the conference tracks for Cloud Expo 2018. Cloud Expo will be held June 5-7, 2018, at the Javits Center in New York City, and November 6-8, 2018, at the Santa Clara Convention Center, Santa Clara, CA. Digital Transformation (DX) is a major focus with the introduction of DX Expo within the program. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive ov...
A strange thing is happening along the way to the Internet of Things, namely far too many devices to work with and manage. It has become clear that we'll need much higher efficiency user experiences that can allow us to more easily and scalably work with the thousands of devices that will soon be in each of our lives. Enter the conversational interface revolution, combining bots we can literally talk with, gesture to, and even direct with our thoughts, with embedded artificial intelligence, whic...
To get the most out of their data, successful companies are not focusing on queries and data lakes, they are actively integrating analytics into their operations with a data-first application development approach. Real-time adjustments to improve revenues, reduce costs, or mitigate risk rely on applications that minimize latency on a variety of data sources. In his session at @BigDataExpo, Jack Norris, Senior Vice President, Data and Applications at MapR Technologies, reviewed best practices to ...
Continuous Delivery makes it possible to exploit findings of cognitive psychology and neuroscience to increase the productivity and happiness of our teams. In his session at 22nd Cloud Expo | DXWorld Expo, Daniel Jones, CTO of EngineerBetter, will answer: How can we improve willpower and decrease technical debt? Is the present bias real? How can we turn it to our advantage? Can you increase a team’s effective IQ? How do DevOps & Product Teams increase empathy, and what impact does empath...
DevOps promotes continuous improvement through a culture of collaboration. But in real terms, how do you: Integrate activities across diverse teams and services? Make objective decisions with system-wide visibility? Use feedback loops to enable learning and improvement? With technology insights and real-world examples, in his general session at @DevOpsSummit, at 21st Cloud Expo, Andi Mann, Chief Technology Advocate at Splunk, explored how leading organizations use data-driven DevOps to close th...
Smart cities have the potential to change our lives at so many levels for citizens: less pollution, reduced parking obstacles, better health, education and more energy savings. Real-time data streaming and the Internet of Things (IoT) possess the power to turn this vision into a reality. However, most organizations today are building their data infrastructure to focus solely on addressing immediate business needs vs. a platform capable of quickly adapting emerging technologies to address future ...
Most technology leaders, contemporary and from the hardware era, are reshaping their businesses to do software. They hope to capture value from emerging technologies such as IoT, SDN, and AI. Ultimately, irrespective of the vertical, it is about deriving value from independent software applications participating in an ecosystem as one comprehensive solution. In his session at @ThingsExpo, Kausik Sridhar, founder and CTO of Pulzze Systems, discussed how given the magnitude of today's application ...
With tough new regulations coming to Europe on data privacy in May 2018, Calligo will explain why in reality the effect is global and transforms how you consider critical data. EU GDPR fundamentally rewrites the rules for cloud, Big Data and IoT. In his session at 21st Cloud Expo, Adam Ryan, Vice President and General Manager EMEA at Calligo, examined the regulations and provided insight on how it affects technology, challenges the established rules and will usher in new levels of diligence arou...
There is a huge demand for responsive, real-time mobile and web experiences, but current architectural patterns do not easily accommodate applications that respond to events in real time. Common solutions using message queues or HTTP long-polling quickly lead to resiliency, scalability and development velocity challenges. In his session at 21st Cloud Expo, Ryland Degnan, a Senior Software Engineer on the Netflix Edge Platform team, will discuss how by leveraging a reactive stream-based protocol,...
Mobile device usage has increased exponentially during the past several years, as consumers rely on handhelds for everything from news and weather to banking and purchases. What can we expect in the next few years? The way in which we interact with our devices will fundamentally change, as businesses leverage Artificial Intelligence. We already see this taking shape as businesses leverage AI for cost savings and customer responsiveness. This trend will continue, as AI is used for more sophistica...
In his session at 21st Cloud Expo, Raju Shreewastava, founder of Big Data Trunk, provided a fun and simple way to introduce Machine Leaning to anyone and everyone. He solved a machine learning problem and demonstrated an easy way to be able to do machine learning without even coding. Raju Shreewastava is the founder of Big Data Trunk (www.BigDataTrunk.com), a Big Data Training and consulting firm with offices in the United States. He previously led the data warehouse/business intelligence and B...
Digital transformation is about embracing digital technologies into a company's culture to better connect with its customers, automate processes, create better tools, enter new markets, etc. Such a transformation requires continuous orchestration across teams and an environment based on open collaboration and daily experiments. In his session at 21st Cloud Expo, Alex Casalboni, Technical (Cloud) Evangelist at Cloud Academy, explored and discussed the most urgent unsolved challenges to achieve f...
"Digital transformation - what we knew about it in the past has been redefined. Automation is going to play such a huge role in that because the culture, the technology, and the business operations are being shifted now," stated Brian Boeggeman, VP of Alliances & Partnerships at Ayehu, in this SYS-CON.tv interview at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
You know you need the cloud, but you're hesitant to simply dump everything at Amazon since you know that not all workloads are suitable for cloud. You know that you want the kind of ease of use and scalability that you get with public cloud, but your applications are architected in a way that makes the public cloud a non-starter. You're looking at private cloud solutions based on hyperconverged infrastructure, but you're concerned with the limits inherent in those technologies. What do you do?
"We started a Master of Science in business analytics - that's the hot topic. We serve the business community around San Francisco so we educate the working professionals and this is where they all want to be," explained Judy Lee, Associate Professor and Department Chair at Golden Gate University, in this SYS-CON.tv interview at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.