In an ideal developer/systems administrator’s world, most applications would deploy seamlessly to multiple platforms and scale elastically with minimal effort bringing the unprecedented agility of the cloud within immediate reach of developer teams and IT organizations.
OpenStack, a RackSpace and NASA initiative, is now managed by an independent foundation and is supported by multiple vendors. It defines APIs for compute, storage, networking, services, monitoring, and additional infrastructure...| By Tim Negris | Article Rating: |
|
| November 30, 2010 07:00 AM EST | Reads: |
6,437 |
Last month, in an article titled, Tiny Company Solves Giant Problem in Cloud-Based Document Management, I wrote about CloudPointe and their unique approach to addressing the perils of cloud-based document management. I looked at how nearly all cloud services that handle documents, media files, and other forms of data suffer from a common weakness: they force customers to entrust their data assets to the cloud service provider and in so doing take on several big, largely unacknowledged risks.
If my article were not enough to draw sufficient attention to this issue, there is an exhaustive new study out that should give enormous pause to organizations considering or already using public cloud services, especially for storing data and documents. The research was conducted by The Centre for Commercial Law Studies at Queen Mary, University of London and it examines the "Ts&Cs" in the service agreements from a who's who of cloud service providers, from Akamai to Zoho.

The survey covers many different aspects of the agreements, including things like jurisdiction, fair use, arbitration, etc., and it finds many troubling details and patterns that lead the authors to conclude:
"The main lesson to be drawn from the Cloud Legal Project's survey is that customers should review the Terms and Conditions of a Cloud service carefully before signing up to it."
Even after signing cloud services agreements, though, the survey shows that, to be as safe as possible, customers should review them again and again. In the words of one of the researchers,
"Perhaps the most disconcerting discovery of the Cloud Legal Project's survey was that many Cloud providers claimed to be able to amend their contracts unilaterally, simply by posting an updated version on the web. In effect, customers are put on notice to download lengthy and complex contracts, on a regular basis, and to compare them against their own copies of earlier versions to look for changes."
Yikes! That makes those slippery packaged software EULAs from pre-cloud days seem like a blood oath by comparison.
Not surprisingly, the survey devotes the most attention to clauses governing data integrity, preservation, disclosure, and location/transfer, and what it finds there is pretty ugly too.
Data Integrity
After acknowledging the natural customer concerns that data placed in a provider's cloud be kept secure against loss, corruption, theft, and unauthorized disclosure, the research report says,
"Our survey found however that most providers not only avoided giving undertakings in respect of data integrity but actually disclaimed liability for it.
"The majority of providers surveyed expressly include terms in their T&C making it clear that ultimate responsibility for preserving the confidentiality and integrity of the data lies with the customer."
Most of the providers' agreements explicitly counsel customers to encrypt their data and to make separate backup arrangements - even in some cases where the service is backup!
To give credit where it is due, though, in this and a number of the research's other dire findings, Salesforce CRM stands out as a paragon of virtue. As with only a few other vendors, it's contract acknowledges the company's responsibility in safeguarding customers' data.
Data Preservation
When a company or consumer entrusts its data to a cloud service they should consider provision in the agreement governing what happens to it in the event the contract is terminated. Can they easily retrieve and transfer the data and will it then be fully deleted from the provider's infrastructure?
The survey shows that most providers fall into one of three categories in this regard.
The providers in one group assert that they will preserve customer data for a set period of time, ranging from 30 days to 3, after the customer terminates their contract. During this grace period, sometimes for an extra charge, the customer can access and off-load the data and at its end the data will be deleted.
The second group of providers asserts that customer data will be deleted immediately when the agreement is terminated. Apple's MobileMe service is in this category and its service agreement dryly states,
"Upon termination of your account you lose all access to the Service and any portions thereof, including, but not limited to, your Member Account (any Subaccounts thereunder), Subscriber ID, email account, iDisk, domains, iChat account and MobileMe Gallery albums. In addition, Apple shall delete all information and data stored in or as a part of your account(s) including, but not limited to, data files, email, albums and preferences."
The survey authors rightly point out how this begs the question of what happens in the event that a court later finds that they termination of the contract was ineffective. They conclude that the service providers in this group may be opening themselves up to civil or criminal liability in some jurisdictions.
Providers in the third group blend conditions found in the first two, acknowledging no obligation to preserve data after a contract has been terminated but also allowing, at their own discretion, an access grace period and/or taking no steps to delete the data at any particular time.
In many cases, though, while providers may not assure that they will keep the data for a grace period or longer, they also do not assure that the data will in fact be deleted, after the grace period or otherwise.
This means that, unless the customer explicitly deletes it after offloading a copy, it may remain in the provider's storage infrastructure for who knows how long. And, for that matter, given the various kinds of redundancy built into many clouds, even if the customer deletes, it that may not mean that it is really gone.
Data Disclosure
Regarding the potential disclosure of customer data to third parties as in the event of a court order or request from law enforcement officials, the survey found the providers to be all over the place. They ranged from doing it without notice at their own discretion at one extreme to giving warning or seeking approval at the other.
For example, the now-defunct G.ho.st service stated that it would disclose customer information if it believed that it would protect its own interest by doing so, and the still-in-business ADrive puts it this way:
"You authorize ADrive to disclose any information about You to law enforcement or other government officials as ADrive, in its sole discretion, believes necessary, prudent or appropriate, in connection with an investigation of fraud, intellectual property infringement, or other activity that is illegal or may expose ADrive to legal liability."
At the other extreme is Salesforce CRM, once again taking the high road. They assure that, unless it is legally prohibited, the customer will be given advance notice of any requested disclosure, and that Saleforce will also assist the customer in opposing such orders. Now, that's what I call "customer advocacy"!
Data Location / Transfer
Many cloud service providers employ multiple, sometimes numerous data centers in different geographic locations to serve their customers. This has led to a variety of legal concerns about customers' data being stored or processed in and across potentially unknown or unregulated jurisdictions.
The EU Data Protection regime does provide strong measures to keep cloud-based data within Europe and certain data, like personal information, within specific countries. But, even in the EU, in-flight data is still at some risk. And, in the US, where the "long-arm" statutes are considerably looser, and in other places, where there are few or no laws as all to govern where and how data is kept and protected, all bets are off.
So, all in all, concerns about privacy and security in relation to data location and transfer are manifest and important to customers, leading the researchers to observe,
"Perhaps surprisingly, given the prominence often attached to these issues, few of the providers surveyed actually undertake to store data in a particular location or zone. [...] Indeed, for the 31 sets of T&C reviewed, 15 made no mention of data location or transit protection whatsoever."
The findings of the research concerning data transfer were similar to those for data location. After acknowledging the international nature of cloud computing and how it means that customer data will usually be transferred between different infrastructure segments over the internet, the report observes,
"Furthermore, if (as many larger Cloud providers do) the provider has multiple data centres, then, unless the provider has built or leased its own secure network and facilities, transfers between data centres may well also be over Internet connections. Several providers (for example, 37Signals, UKFast) caution in their T&C that customer data may be transferred unencrypted over inherently insecure networks in such a manner."
Losing My Religion
Cloud computing, especially public cloud computing, has many potential benefits but is not without its weaknesses; and, those weaknesses tend to fall into two categories.
There are issues that vendors and customers both readily acknowledge and are working hard to address. The need for better access security and more management automation fall into this category and will likely be fixed by incremental technical improvements and new products that address them.
Then, there are issues like the subject of this article. They are ones with little consensus, where most providers are either defiant or in denial, most customers are uninformed or un-empowered, and hardly anybody recognizes that the problem may stem from flawed fundamentals.
Most cloud service providers and most of their customers might find it patent heresy to question the soundness of the idea of putting data and documents into the cloud. After all, for many that is the very purpose of the cloud, full stop. If you take back the information assets and put them on a disk array that you own and control, what is left?
There is a lot left, actually. There is a processing and communications fabric to which most cloud benefits still accrue, and to a greater degree than they do for the comparative commodity of data storage.
The reason the data is in the cloud by default is not because that makes the most sense. It is because Fibre Channel, Infiniband, and other schemes for directly connecting disks to processors are way faster than those for connecting the nodes of a wide area network. If that were not true, would everyone still think that the data belongs in the cloud? I doubt it.
Vendor lock-in, regulatory compliance, privacy, and security are the greatest customer concerns about the public cloud and they are all made considerably worse by the requirement that information assets be placed in the cloud.
CloudPointe already makes a strong case for taking back the documents and files. WAN connection speeds and the way such information assets are used are both very amenable to sending them through the cloud but not keeping them there. It may just be a matter of time before improved connection speeds and more advanced distributed database technology allow the same possibilities for other kinds of data.
Published November 30, 2010 Reads 6,437
Copyright © 2010 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Tim Negris
Tim Negris, is VP Marketing at 1010data, a provider of a cloud-based Big Data analytics platform. He occasionally authors software industry news analysis and insights on Ulitzer.com, is a 25-year technology industry veteran with expertise in software development, database, networking, social media, cloud computing, mobile apps, and other enabling technologies. He is widely recognized for ability to rapidly translate complex technical information and concepts into compelling, actionable knowledge.
He is widely credited with coining the term and contributing to the concept of “Thin Client” computing model while working for Larry Ellison in the early days of Oracle.
Tim has also held a variety of executive and consulting roles in a numerous start-ups, and several established companies, including Sybase, Oracle, HP, Dell, and IBM. He is a frequent contributor to a number of publications and sites, focusing on technologies and their applications, and has written a number of advanced software applications for social media, video streaming, and music education. He can be reached at tim (at) negris.com @timnegris
In an ideal developer/systems administrator’s world, most applications would deploy seamlessly to multiple platforms and scale elastically with minimal effort bringing the unprecedented agility of the cloud within immediate reach of developer teams and IT organizations.
OpenStack, a RackSpace and NASA initiative, is now managed by an independent foundation and is supported by multiple vendors. It defines APIs for compute, storage, networking, services, monitoring, and additional infrastructure...May. 19, 2013 05:00 PM EDT Reads: 1,378 |
By Jeremy Geelan Companies around the world are moving into on-premise private cloud environments. Many connect their private cloud to their public cloud service providers. In his session at 12th Cloud Expo | Cloud Expo New York [June 10-13], Brian Patrick Donaghy will talk about examples of what worked, what failed and why we should think about this evolution.May. 19, 2013 04:00 PM EDT Reads: 1,902 |
By Liz McMillan Enterprise cloud adoption revolves around pushing the BYOD movement and focusing on data security.
In his session at the 12th International Cloud Expo, Ross Brouse, COO and President of Solar VPS, will cover how cloud adoption is driven by consumerism, humanity’s need to socialize, our addiction to new gadgets and the ability of data to stay secure in a growing collaborative world. The cloud is a drug and we’re just getting hooked.
Ross Brouse is the COO and President of Solar VPS. He is a tr...May. 19, 2013 02:00 PM EDT Reads: 1,225 |
By Jeremy Geelan Organizations across the world are increasingly starting to see the benefits of moving more and more services to the cloud. The focus on the cost-saving potential of cloud is rapidly shifting to completely transforming the business with cloud. As organizations are investing enormous sums on technology they are starting to realize that in order to maximize the return on investment and accelerate the business transformation process the first area of focus should be people. By ensuring the organiza...May. 19, 2013 02:00 PM EDT Reads: 1,601 |
By Jeremy Geelan May. 19, 2013 02:00 PM EDT Reads: 2,416 |
By Jeremy Geelan May. 19, 2013 01:00 PM EDT Reads: 3,522 |
By Jeremy Geelan Our more interconnected planet is accelerating the adoption and convergence of next-generation architectures, in the form of cloud, mobile and instrumented physical assets. Organizations that can effectively balance optimization and innovation, will be in a position to leverage new systems of engagement, out maneuver their peers and achieve desired outcomes. In the Opening Keynote at 12th Cloud Expo | Cloud Expo New York, IBM GM & Next Generation Platform CTO Dr Danny Sabbah will detail the crit...May. 19, 2013 01:00 PM EDT Reads: 2,862 |
By Pat Romanski The cloud-enabled data center sits at the center of IT transformation. It facilitates the interconnection and communities that come together, propelling growth for both buyers and sellers.
In his session at the 12th International Cloud Expo, Gerry Fassig, CoreSite’s Vice President of Sales, will discuss how CoreSite is bringing together best-of-breed partners through the Open Cloud Exchange resulting in public, private, and hybrid cloud interconnection and management as well as connectivity to...May. 19, 2013 01:00 PM EDT Reads: 1,294 |
By Jeremy Geelan Companies around the world are collecting massive amounts of data everyday that’s sitting around and not being utilized. Take for example the fact that companies collect demographic and location-based data via mobile devices all the time, but have to figure out how to monetize that data. In this session, Joyent CTO and founder Jason Hoffman will examine the state of Big Data, taking a look at what we're doing now to discussing what's on the horizon, as companies prepare and realign their busines...May. 19, 2013 01:00 PM EDT Reads: 1,114 |
By Jeremy Geelan The massive computing and storage resources that are needed to support big data applications make cloud environments an ideal fit. In Nati Shalom's upcoming session at 12th Cloud Expo | Cloud Expo New York [June 10-13, 2013], you'll learn how to build your big data "database on-demand" using MongoDB, Cassandra, Solr, MySQL, or any other big data solution, as well as manage your big data application using a new open source framework called “Cloudify.” All this, on top of the OpenStack cloud. May. 19, 2013 12:00 PM EDT Reads: 2,401 |
- Cloud People: A Who's Who of Cloud Computing
- Cloud Expo New York Speaker Profile: Dave Linthicum – Cloud Technology Partners
- Cloud Expo New York: Cloud Is Changing the Economics of Business
- Cloud Expo New York Speaker Profile: Nicos Vekiarides – TwinStrata
- AMD and Adobe Collaborate on Upcoming Version of Adobe Premiere Pro Software to Enable Breakthrough Video Editing Performance Through Open Standards
- Windows Azure IaaS Reaches General Availability
- State and Local Governments Adopt Microsoft Dynamics CRM to Improve Citizen Service Delivery
- New Relic Q1 2013 Blazes Past Growth Targets and Reaches 40,000 Active Customer Accounts
- Enterasys Spotlights SDN's Impact on Traditional Networking in Upcoming Webinar
- Best CIO Practices Shared from SHI’s Customers
- Cloud Expo New York: Delivering Digital Marketing on the Cloud
- Cloud Expo New York: Deploying Hybrid Cloud for Performance and Uptime
- Cloud People: A Who's Who of Cloud Computing
- Cloud Expo New York: Best CIO Practices Shared from SHI’s Customers
- Cloud Expo New York Speaker Profile: Dave Linthicum – Cloud Technology Partners
- Cloud Expo New York Speaker Profile: Jill T. Singer – NRO
- Cloud Expo New York Speaker Profile: Greg O'Connor – AppZero
- Examining the True Cost of Big Data
- Cloud Expo New York: Cloud Is Changing the Economics of Business
- Cloud Expo New York: How to Use Google Apps Script
- Cloud Expo New York Speaker Profile: Nicos Vekiarides – TwinStrata
- Cloud Computing Bootcamp at Cloud Expo New York
- AMD and Adobe Collaborate on Upcoming Version of Adobe Premiere Pro Software to Enable Breakthrough Video Editing Performance Through Open Standards
- Windows Azure IaaS Reaches General Availability
- The Top 150 Players in Cloud Computing
- What is Cloud Computing?
- Six Benefits of Cloud Computing
- The Top 250 Players in the Cloud Computing Ecosystem
- Twenty-One Experts Define Cloud Computing
- What's the Difference Between Cloud Computing and SaaS?
- Virtualization Conference Keynote Webcast Live on SYS-CON.TV
- The Future of Cloud Computing
- A Brief History of Cloud Computing: Is the Cloud There Yet?
- GDS International: Global Warming Scam?
- Cloud Expo Europe 2009 in Prague: Themes & Topics
- Cloud Computing Expo 2009 West: Call for Papers Now Closed








Companies around the world are moving into on-premise private cloud environments. Many connect their private cloud to their public cloud service providers. In his session at 12th Cloud Expo | Cloud Expo New York [June 10-13], Brian Patrick Donaghy will talk about examples of what worked, what failed and why we should think about this evolution.
Enterprise cloud adoption revolves around pushing the BYOD movement and focusing on data security.
In his session at the 12th International Cloud Expo, Ross Brouse, COO and President of Solar VPS, will cover how cloud adoption is driven by consumerism, humanity’s need to socialize, our addiction to new gadgets and the ability of data to stay secure in a growing collaborative world. The cloud is a drug and we’re just getting hooked.
Ross Brouse is the COO and President of Solar VPS. He is a tr...
Organizations across the world are increasingly starting to see the benefits of moving more and more services to the cloud. The focus on the cost-saving potential of cloud is rapidly shifting to completely transforming the business with cloud. As organizations are investing enormous sums on technology they are starting to realize that in order to maximize the return on investment and accelerate the business transformation process the first area of focus should be people. By ensuring the organiza...
Our more interconnected planet is accelerating the adoption and convergence of next-generation architectures, in the form of cloud, mobile and instrumented physical assets. Organizations that can effectively balance optimization and innovation, will be in a position to leverage new systems of engagement, out maneuver their peers and achieve desired outcomes. In the Opening Keynote at 12th Cloud Expo | Cloud Expo New York, IBM GM & Next Generation Platform CTO Dr Danny Sabbah will detail the crit...
The cloud-enabled data center sits at the center of IT transformation. It facilitates the interconnection and communities that come together, propelling growth for both buyers and sellers.
In his session at the 12th International Cloud Expo, Gerry Fassig, CoreSite’s Vice President of Sales, will discuss how CoreSite is bringing together best-of-breed partners through the Open Cloud Exchange resulting in public, private, and hybrid cloud interconnection and management as well as connectivity to...
Companies around the world are collecting massive amounts of data everyday that’s sitting around and not being utilized. Take for example the fact that companies collect demographic and location-based data via mobile devices all the time, but have to figure out how to monetize that data. In this session, Joyent CTO and founder Jason Hoffman will examine the state of Big Data, taking a look at what we're doing now to discussing what's on the horizon, as companies prepare and realign their busines...
The massive computing and storage resources that are needed to support big data applications make cloud environments an ideal fit. In Nati Shalom's upcoming session at 12th Cloud Expo | Cloud Expo New York [June 10-13, 2013], you'll learn how to build your big data "database on-demand" using MongoDB, Cassandra, Solr, MySQL, or any other big data solution, as well as manage your big data application using a new open source framework called “Cloudify.” All this, on top of the OpenStack cloud.
New technologies allow schools, colleges and universities to analyze absolutely everything that happens. From student behavior, testing results, career development of students as well as educational needs based on changing societies. A lot of this data has already been stored and is used for statist...
A recent Gartner study states that the function of the modern CIO is in flux and that his or her future focus must incorporate digital assets (aka cloud-based data and applications) to remain relevant. Towards the goal of riding the sea change a compiler of stacks to a broker of business needs, secu...
In the coming years, big data will change the way organisations and societies are operated and managed. Big data however, is not the only trend that will impact significantly how organisations operate. Another major trend at the moment is gamification. Gamification will change the way organisations ...
We all talk about cloud differently, but is there a way we should be speaking about this tech?
Cloud computing is now a widely reported, if not accepted, IT movement that, depending on who you talk to, has changed or is changing the way businesses utilize infrastructure.
The age of data center automation is upon us. Whether it's cloud or SDN or devops in general, automation as a means to achieve efficiency and, one hopes, free up resources that can be then redirected to focus on innovation.
As is always the case when we begin to move further upwards, abstracting ...
Windows Azure Virtual Networks offers the power to open up several cross-premises use case scenarios, including Active Directory Disaster Recovery, SQL Database Replication, Windows Server 2012 DFS-R File Replication, Accelerated Cloud File Services with BranchCache, Hybrid Web Applications and MORE...
As the infrastructure cloud market (IaaS and PaaS) continues to grow rapidly, we are seeing quite a few customers who are delivering an application – whether it is a mission-critical or SaaS application – and basing their solution on VMware.
VMware Security Cloud Encryption cloud keyboard Cloud Enc...
Have you heard of products like IBM’s InfoSphere Streams, Tibco’s Event Processing product, or Oracle’s CEP product? All good examples of commercially available stream processing technologies which help you process events in real-time.
I’ve been asked what I consider as “Big Data” versus “Small Dat...
My fellow Technical Evangelists and I have authored a content series that steps through building your very own Private Cloud by leveraging Windows Server 2012, our FREE Hyper-V Server 2012, Windows Azure Infrastructure Services ( IaaS ) and System Center 2012 Service Pack 1.
Week-by-week, we walk ...















