eweekchat

Next-Gen Cloud Services
JOIN US: This is a chat-based conversation about new types of cloud (and cloud delivery) services, which are becoming more pervasive and diversified than ever. We are becoming more dependent on the cloud each day--especially during the COVID-19 pandemic. Join us!
   6 years ago
#eweekchatNext-Gen Networking TrendsJOIN US: This is a chat-based conversation about trends in new-generation networking in which we will discuss the impact of SD-WAN, 5G, WiFi6 and other factors in moving data from one node to another--and another--and another.
   6 years ago
#eweekchatConfidential ComputingJOIN US: This is a chat-based conversation about how a newly recognized trend in IT security that follows data all the way through the transom and protects it at every stage--including when it's processing. Join us!
Chris Preimesberger
I think I'll put together a compilation of highlights from this chat for an eWEEK story soon!
Phil Straw
Good to take part, thanks Chris. Let me know if you need anything more.
Larry Lunetta
Great discussion. Thanks everyone.
Bruce Kornfeld
Thanks for having me today, Chris. Let me know if there are any followup questions.
Chris Preimesberger
This has been a great and informative discussion. Outstanding interaction and engagement. Want to thank each of you who brought a perspective, opinion or data point to our community round table today.
Phil Straw
Data infrastructure is about to change dramatically as it becomes more decentralised outside of the hyperscalers. We'll need to deliver architectures that deliver new levels of performance, mgmt and security in places data centers didn't used to be.

(edited)

Chris Preimesberger
We've 10 mins left, how about some final thoughts and perhaps some takeaways you got from this session?
Bruce Kornfeld
Lots of great perspectives here. End users have it hard - where to run each application to optimize cost, performance and security. Cloud is a huge market because it solves many problems, but causes some others. Edge is growing because some apps just need to be local
Sean Leach
really enjoyed hearing everyone's thoughts/opinions. At the end of the day, no matter which technology is better - all of this competition helps drive better end user experiences, better security and better development environments
Tony Cai - Nerdio
@brucekornfeld I would say cloud opens up many more things to consider, that often doesn't get considered until post implementation.
Phil Straw
@brucekornfeld Not just the apps - but the data too
Larry Lunetta
I think it is clear from the discussion that "cloud" now encompasses the entire IT ecosystem. What makes Hybrid Cloud possible is the ability to seamlessly manage workloads from the edge to data center to private cloud to public cloud.
Eric Han
Final takeaway: we're all talking about cloud and how it changes customers and products we build. Great to have broad point of views. More debates is better. @editingwhiz
Bruce Kornfeld
@TonyCai long live the cloud!
Chris Preimesberger
Q5: How can companies determine the right balance between the need for speed and the necessity to stay up-to-date in cloud technologies, when business context changes basically every day?
Phil Straw
A5 Cloud has lots of advantages, like operational up time, resilience, worldwide but local geographies (eg. CDN), elastic scale etc. Slower moving but established services that need scale are easily bought as “rented” outcomes.
Phil Straw
Fast moving business context and technical solutions may be better placed in the context of addition via Hybrid cloud or edge compute ?
Chris Preimesberger
Good point, Phil. Sounds like an entire strategy for apps, functionality and cloud/edge/IoT points needs to be coordinated at the top.
Sean Leach
a5: From what we have seen from our most progressive customers, a dependable CI/CD pipeline, automated testing, immutable infrastructure, and DevOps/DevSecOps practices have all been common themes for their ability to deploy rapidly and safely
Larry Lunetta
A5: By consuming cloud services "as a Service", organizations rely on the provider to deliver what they need. This implies the provider will know how and when to introduce new technologies.
Tony Cai - Nerdio
A5: Companies need to evaluate whether staying up to date means a detriment to their business or can they effectively manage those changes and balancing moving quickly with adequate change management.
Phil Straw
@TonyCai Should I stay or should I go ;-)
Eric Han
A5: disrupt yourself is always easier to say than to do. Hopefully, there's teams doing that and they're given enough rope. Level of invest can be set to market pace, but we all read about black swan events that upend all that. @editingwhiz
Tony Cai - Nerdio
A5: Of course COVID forced a lot of Digital Transformation in a short amount of time.
Chris Preimesberger
Jeez, we hardly mention COVID here today -- could do a whole chat on it!
Bruce Kornfeld
@TonyCai It really is amazing. Work from home, not wanting (or being able) to add infrastructure to datacenters...its a whole new world for users trying to navigate all of this...urgently!
Nick Brackney
A5: Realize the answer is always "it depends", realize multiple environments is your reality, and try and limit complexity without hampering the business. Be flexible, and realize incremental gains are better then sweeping mandates that impose a lot of risk.
Chris Preimesberger
Absoutely, Nick. But a high-level, clear-headed headed strategy identifying all alternatives is necessary, ya think?
Chris Preimesberger
Q5: why, it's right around the virtual corner ...
Chris Preimesberger
Q4: What are some new approaches vendors are using to ensure safe delivery of cloud services and to add value with ancillary features?
Phil Straw
A4 Cloud is now established enough that vendors are now designing for cloud specifically. This helps a lot because retrofitting security is often hard or impossible.
Phil Straw
A4 As cloud, edge and indeed hybrid emerges as the norm a more holistic approach to security is possible for the same reason.
Phil Straw
A4 Cloud is one piece of the puzzle and securing it as as much about all the things that touch it, including enterprise and edge. SoftIron does this with storage products to enable a continuum that is coherent for data assets in all locations.
Larry Lunetta
A4: Organizations are moving to a Zero Trust framework which relies on identity-based access control and much tighter security integration between the end point and the application.
Bruce Kornfeld
A4: Another area is for users to leverage encryption from cloud providers, but not trust them with the keys. BYOK is a movement that is starting to take hold with Cloud.
Nick Brackney
A4 I was a fan of VMware's approach before I ever got to Dell. I think abstraction and building in security is the way to go in simplifying and ensuring safety. But biggest thing is closing the gaps and burden on customers of Shared Responsibility Models.
Chris Preimesberger
Do you think identity control and access is ultimately the most efficient way to secure anything?
Eric Han
A4: vendors are building for and like clouds now. so good question and I think small (in terms of visibility but large in impact) has been continuous release/update (which adds to the security goal). More to where you question might be asking is also providing viz @editingwhiz
Larry Lunetta
A4: To add value, vendors are adding AI-based capabilities to deal with the complexity of a hybrid cloud world. AI is now cutting down the number of trouble tickets reported and reducing the amount of time to resolve them.
Eric Han
A4-cont: and knowing the state of deployments, as to the value-add. @editingwhiz
Tony Cai - Nerdio
A4: Double encryption in transit and at rest as a feature, enforcing MFA as a standard, PaaS hosted connection gateways with built in security managed by the vendor. Microsoft has started to enforce their partners to beef up their security all around.
Nick Brackney
Identity and Access Management is absolutely critical especially Privileged Identities. However it, and networking are battling it out for the most overlooked area needed, based on what I see.
Sean Leach
a4: A big area of R&D is around the safe delivery of applications in multi-tenant environments-maintaining performance/security. Technologies like WebAssembly/WASI are scalable/powerful technologies that provide high performance isolation - as opposed to docker etc.
Bruce Kornfeld
end users can now run their own key managers for all their encryption use cases - now extending to cloud.

(edited)

Chris Preimesberger
Can BYOK security become problematic due to presumed complexity, or is that actually an issue?
Eric Han
IdAM is a must and a building block. Otherwise, we don't have a lot to act on. @editingwhiz
Sean Leach
a4: TLS 1.3 is another key technology that improves performance and security at the TLS level
Nick Brackney
agreed @brucekornfeld given the way that governments have treated data sovereignty and gag orders you'd have to be very foolish to hand over the security keys to a vendor. They can be compelled to divulge your info and have to keep it from you.
Larry Lunetta
A4: Identity-based access control is the starting point for a "defense in depth" approach to security. No one technique will be sufficient to achieve something like Zero Trust, but it definitely is a foundational element.
Tony Cai - Nerdio
A4: RBAC - Role based access control as well.
Bruce Kornfeld
Key management CAN be very complex. Each use case can have thousands or millions of keys. Third party key managers are designed to remove that complexity, and now they can also work with cloud app - and cloud providers are supporting it.
Eric Han
@larry_lunetta agreed. Not my article but I liked this read from @stackrox on some on the container space. https://www.stackrox.com/post/2020/08/guide-to-gke... #stackrox
https://www.stackrox.com/post/2020/08/guide-to-gke-runtime-security-for-gcp-workloads/
Guide to GKE Runtime Security for GCP Workloads | StackRox: Kubernetes and container security solution
Guide to GKE Runtime Security for GCP Workloads | StackRox: Kubernetes and container security solution
This guide discusses GKE runtime security recommendations and best practices to help harden K8s and protect your cloud-native apps
Bruce Kornfeld
@NickBrackney Agreed. It kind of amazes me that this is so prevalent today. So many cloud apps out there where the customer just "turns on" encryption and maybe doesn't realize the vendor has the keys as well.