Showing posts with label Cloud. Show all posts
Showing posts with label Cloud. Show all posts

Friday, May 05, 2017

Magical Layers Of Sunset At Tampa Bay Florida - IMRAN™

Magical Layers Of Sunset At Tampa Bay Florida - IMRAN™
What magic Tampa Bay Florida sunsets reveal in layers that I am blessed to see.
The base photo of this image is SOOC (straight out of camera) of my 10 years old Nikon D300. No editing. No color tweak of ANY kind. No filters. It was simply cropped and I added text to fit it into a FaceBook Cover Photo format.

© 2017 IMRAN™  

Tuesday, May 10, 2016

Forget Public, Private & Hybrid, It Is Time To Reclassify Cloud Classifications


In my life is a private consultant to large clients and later also as an enterprise architect at the world's best software company in my day job, I have been trying to explain to people why Private/Public/Hybrid is not fully accurate in terms of Cloud classifications. (I am not even talking about Community Cloud in this post).

My position on Cloud is that we have Public, Private (including Hosted Private). and two more... What everyone calls Hybrid is what I say really should be called Parallel, and Hybrid should be the name given to a separate type.

By Parallel I am referring to companies using Private cloud for some functions, and Public cloud for other applications. There is likely no interaction between the two. The overall benefit is a compromise between the best of both Public and Private, in a sort of "weighted average" way.

What we SHOULD be calling Hybrid would be the case of enterprise architectures that span public and private clouds for one or a set of interoperating or integrated business applications. For example, if a firm uses private cloud for running its mission critical business application, but that application seamlessly also moves specific parts of its workload to and from a public cloud. Here is a rudimentary example. A stock trading firm uses its own high performance trading applications on its own private cloud platform.  But the private cloud hosted apps ship some parts of their work, e.g. less time critical analysis of large data sets, to a public cloud big data crunching services provider.

You can see that this has far deeper integration between private and public cloud uses and is clearly different from a company running all mission critical applications on a private cloud but, say, simply using outlook.com or gmail for business email. The latter is a good use of Parallel cloud computing.


Enhanced by Zemanta

Sunday, April 10, 2016

Double Trouble! - IMRAN™

Double Trouble! - IMRAN™ — Dual Dramatic Cloud Formation Over Long Island Home Beach. (Cick to see the full photo). ...

Posted by Imran Anwar on Saturday, April 9, 2016

Wednesday, July 15, 2015

Another Brick In The (Fire)Wall Versus The Great Wall Of Red China! - IMRAN™


Another Brick In The (Fire)Wall Versus The Great Wall Of Red China! In 1998-1999 I had the privilege of being the first...
Posted by Imran Anwar on Wednesday, July 15, 2015

Wednesday, June 03, 2015

Love The Cloud With No Limits, But Know Your Limits!

I just read an article on Forbes' site where the writer correctly argued that despite the cost of cloud storage being nearly zero (who can compete with "Free!" ?) he likes to use personal networked storage at home for his data.

I agree with the points he makes about why using personal storage is still the better option versus cloud storage. But I disagree on the use of Network Attached Storage at home. No matter what device I have tried, no NAS at home comes close to the speed of a Thunderbolt, Firewire or USB3 external hard drive when doing regular and incremental backups of my Macs and MacBook Pros, as I do.

Coincidentally, one of the biggest problems I have with cloud storage is that despite buying cool utilities like ExpanDrive. which mount my Google, Box, DropBox OneDrive, FTP and other cloud storage on my Macs's desktops as local drives, none of them is writable from backup apps like Carbon Copy Cloner or Time Machine.

Additionally, the time it would take for my backups to complete even over my 75/75Mbps connections is another huge deterrent.

I personally carry 2 portable drives (one ThunderBolt and one USB3) with my laptops when I travel, while having multiple clones and Time Machine backups at both homes in NY and FL. Each is obviously encrypted with the highest level security, or I would be trading reliable backup with high risk of theft.

No matter what you do and what type of data you have, whether on a phone or a computer, you MUST backup your data, if you value your time, and your data. As Clint Eastwood would say, A man's gotta know his limits. So does a woman.

Can you afford to lose all the data on your device? Pictures? Messages? Emails? Contacts? How much spare time did God give you that you'd want to take on the burden of re-gathering all the contacts you have? And what about the photos? You do have them backed up somewhere, right?

Don't tell me you are relying on FaceBook as your personal album storage? What if someone hacks your account and deletes all your albums? Even worse, what if the FB policy Nazis don't like something you post and delete your account?

By the way, did you know that FaceBook turns your gorgeous 1-15MB photos taken with anything from a cell phone to a fancy camera into pure-crap-minimum-tolerable-quality 72 dpi files of merely 100-200KB? Good luck printing those if you ever want to in the future. Even a USB stick or two are so cheap these days. Not using at least a Thumb Drive is Dumb!

At the very least use something like Flickr, that stores the images at full size and gives you 1TB free. But check your security settings so none of your private photos become public. (Well, it is OK to give me access to see them. Purely for my giving you security advice of course. LOL).

Finally, remember, One is never enough, and as I also always say, Once Every Night isn't enough either. :-) I learned a long time ago that when a laptop drive dies, it will happen on the same day an external backup drive will also die ...and the backup of the backup will be unmountable on that same day. ;-)

So, backup on more than one system (external drive, thumb drive, CD/DVD/Blu Ray, cloud), with more than one method (data only, full clone, incremental timestamped backups), in more than one place (your home, your parents' home, across the country).

One day (or night) you will thank me for it!

Imran Anwar
Love The Unlimited Cloud, But Within Limits!™
Cloud 9 Global Inc.
IMRAN.TV

Tuesday, September 13, 2011

Question The Tough Questions To Ask In Cloud Computing

I am on record as suggesting that tough questions need to be asked by everyone (including clients, media AND vendors) before jumping on the Cloud Computing bandwagon. (See http://www.youtube.com/watch?v=uYl-tzTHtQk which I recorded even before having a day job at the leading Cloud Computing Converged Infrastructure vendor.)


I read a recent article, Some tough questions you need to ask your cloud provider,  by Rutrell Yasin. It is in the respected GCN (Government Computer News), a publication I also recall being interviewed by in the past. That was during my days of being CEO, EverTrac, the pioneer in location-aware eBusiness solutions, including tracking people and assets, indoors and outdoors, in the late 1990s.

In it, the writer quotes Wolf Tombe, chief technology officer within the Customs and Border Protection’s Office of Information Technology. I am certain Mr. Tombe is far smarter, more experienced and clout-carrying in government, technology, and probably even Cloud Computing circles than I am.

But, I also respectfully disagree with his contention that some applications are "easy wins moving to the cloud, such as e-mail and collaboration tools".

If "easy" refers to how quickly and conveniently an app can be deployed onto a cloud or converged infrastructure, then I would say, most apps, whether email, or ISV created vertical solutions, can be migrated with reasonable convenience and the expected amount of work.

If the contention is that somehow email and collaboration are no brainers to put in the public cloud, I strongly disagree.

I think that is over simplistic and dangerous. What apps are no-brainers to move to the public cloud should depend on the mission-critical or sensitive nature of the data or functionality in the app, not what the app itself is.

For example, even the simple email and internal discussion files of a nuclear weapons design agency with just 100 people would be far more critical to protect than, say, all the accounting data of a widget making company with 5000 employees.

So, as I have said before, tough questions need to be asked... by clients, by media, and even by vendors. The stakes are too high, the opportunity for Cloud Computing to be a globally beneficial tool is too huge, and the threats too serious, for any of these elements to be glossed over.

Technorati Tags: , , , , , , , ,



Monday, November 29, 2010

On Securely Making Cloudy Claims About Cloud Security

PC World reported on the speech by a former hacker known as MafiaBoy, who was arrested for lots of insidious activities. Now, he was a guest speaker, in Toronto, Canada, at a forum organized by a well-known Japanese storage vendor.

His contention was that Cloud Computing has serious security vulnerabilities and that Security is an afterthought among vendors.

I am certain the reformed hacker is a very, very, smart man. I am positive, no amount of security can be enough to ever guarantee perfection. However, the whole approach and message was a bit yawn-inducing for me. He was restating the obvious, wrapped in a bit of irresponsible FUD (fear, uncertainty, doubt), with a ribbon of future "I told you so" claims tying it up nicely.

That is like someone being arrested for throwing medical trash into a town's water tank, and then going on CNN or Fox News Channel to make a generalized claim, like, "There are serious vulnerabilities in our whole nation's public drinking water supply." That person can then sit back while people wonder if they should all be drinking bottled water only.

Some of the other contentions of people who like hearing that kind of message, commenting at the PC World site, were that Cloud Computing is nothing but Client Server with a new label. OK, if someone said Cloud Computing is sort of like On-Demand Computing — but with both the ON and the DEMAND parts kicked into high gear in the marketplace — I would have agreed a bit.

Yes, of course, many of the concepts of Cloud Computing are derived from the evolution of previous computer system architectures and paradigms. But, if Cloud Computing is exactly the same as Client-Server, then it is even more "same" as mainframes and dumb terminals of yester-century.

For the first time in modern history, the true power of the Internet can be harnessed by every one, and every business, at every level, for almost every function, with the same type of access previously only giant multinationals could afford.

Even with the Internet boom, the overall benefits to us, ordinary people, were limited in type and scope.

We could enjoy email accounts of our own. With a bit of web hosting, using $5 per month packages, we could put up web sites as slick as the biggest multinationals (whether someone ever visited our web sites or not).

But, we could not venture into scaling beyond those basic limits.

A company with 20 employees could not afford true ERP or CRM solutions. An art movie studio with 5 creators could not expect to take on a movie requiring 10,000 hours of rendering time, without their idea being passe' while their 5 PCs or Apple Macs chugged along for 5 years.

Now they can rent software as a service (SaaS), platform as a service (PaaS), or a ton of infrastructure as a service (IaaS) as and when they need, without needing a million Dollars budget.

These, and countless other, aspects of cloud computing are leveling the playing field for individuals and the smallest businesses, which no Client Server solution did.

The benefits big business are gaining from Cloud Computing are even more obvious. From hardware and software license cost savings, to energy savings, to better utilizing available resources with available headcount, reducing total cost of ownership for once without having to resort to the typical head count reductions of past years, are just a few. Quick provisioning of application development and test environments, in hours, affordably, and then spooling it down, are additional examples.

So, going back to our esteemed and honorable ex-hacker's contentions about Security, let's ask: Is Security important? No. It is not important, it is ESSENTIAL.

But, for anyone to say that Cloud vendors are thinking of security as an afterthought is absolutely ridiculous. It is even more silly posturing than politicians of all parties typically indulge in, with meaningless statements that raise their audiences' fear levels. Just recently I wrote a popular item, which discussed the Cloud Security Alliance's good work, especially in the area of enabling greater levels of governance, risk management and compliance in Cloud.

An important thing to keep in mind is that Next Generation Data Centers, with highly converged and virtualized infrastructures, are not being created out of thin air, with paper, glue and paint. They are being created by integrating, and hardening, existing parts of the solution stack - virtualization, network, compute, and storage.

None of these elements consists of some untested new gadget created in a lab by two geeks and their dog. Each element has industry leaders, and strong competitors. Each has its own security postures, needs and mechanisms. And, vendors who are putting together the entire vertical stack, either from in-house, or partner technologies, are all working to build additional wrappers of Security. Trusted Multi-Tenancy, authentication and access control, encryption of data at rest and in flight, are just some examples of additional wrappers being built around the "core-stack" and what is in the "box".

Is this all perfect? Of course not? But, even the most secure, non-cloud, current data centers of big corporations have shown how Security can be breached.

From millions of credit card numbers being stolen, to WikiLeaks, even when Security is the most talked about topic, e.g. in financial services, government, military, healthcare, etc., some "misguided" (read malicious) person can find a way into any system, or may already be inside the system (as an employee).

What is required is for people like the former hacker to specify examples of where they see major vulnerabilities, how they would fix them, or how they suggested the fix and some vendor(s) or clients did not listen. I will be happy to take him to industry leaders at industry leading companies even better known than the large firm he was a guest of.

But, then, he better have some specific risks and vulnerabilities identified, with specific recommendations and proposed solutions. Otherwise, there are plenty of people who can sit outside complaining about a "problem" without being part of a "solution." Who has got time for those.

What do you think vendors need to pay more attention to, immediately, to make Cloud Computing more secure?

===


Imran Anwar is founder of Internet email in Pakistan, co-founder and co-owner of the .PK ccTLD of Pakistan, and founder of the credit card industry there. As a New York based technology, cloud computing, strategy, marketing, media and business professional he is often seen and heard on global media like CNN, Fox News, Express TV, WWRL and many others. These are Imran's personal opinions and do not necessarily reflect those of any employer, parent company, client, family member or other persons or organizations. Phew!


Technorati Tags: , , , , , , , , ,



Wednesday, November 17, 2010

Governing Governance, Risking Risky Analysis Paralysis & Complying With Compliance In Successful Cloud Computing Initiatives

The Cloud Security Alliance, just announced a new stack to address issues of governance, risk management and compliance for the nascent but exploding cloud computing industry. InformationWeek has a good short news report on the subject.

I consider this welcome news, from two perspectives - as an individual professional opinion; and as the opinion of someone leading vertical solutions and service provider offers planning & management, at an industry-leader cloud technology company.

Cloud Computing has been fortunate that its hype only slightly exceeded the real world benefits it provides, and its ad-hoc, vendors and clients deciding what's best for them, implementation of governance, risk and compliance management were "just good enough" to keep the ball rolling. For early adopters, and for those seeking immediate TCO (Total Cost of Ownership) and ROI (Return On Investment) value of next generation data center models, with highly converged virtualized infrastructure, this was not a show stopper.

But, for the Cloud industry to evolve to the next stage, where it literally can explode to the stage, which would make the latest set of analyst predictions, such as those quoted in the article above, actually likely to come true, governance, risk and compliance issues had to be addressed sooner rather than later.

The challenge in every new paradigm (or even what some consider a repackaged old paradigm enabled by technology capabilities that enable the concept to take off this time) is to balance between extremes along those three lines of concerns.

I have called attention to these topics in the past in print and online. My concern has been that overly excited buyers, and sell-at-all-costs vendors could lead to risky behavior on one side of the spectrum, while analysis paralysis would keep a huge majority from losing out on the benefits of cloud computing.

What is needed, as I have said before, is a pragmatic and practical approach; rather than utopian and impossible drives for perfection, that cannot be achieved in one, much less, three areas of importance like GRC. Add to that the complexity and impossibility of agreement, a situation in which every stakeholder brings their own colored and colorful viewpoint.

The need is for comprehensive, but not onerous, approaches to governance; risk management without seeking absolute, "perfect", impossible to achieve, levels of "zero risk"; and compliance standards that enable enterprise and service provider moves to cloud models, rather than being roadblocks. These are are all essential steps without tripping up clients or vendors.

The CSA's latest contribution to successfully achieving these is a free GRC stack, a set of toolkits, for enterprise customers, vendors of cloud & security solutions, as well as those tasked with auditing IT. The toolkits are, Cloud Audit, Cloud Controls Matrix and the Consensus Assessments Initiative Questionnaire (Apparently they did not spend much time on coming up with a better name for this last one!). You can download the GRC stack free.

This is not, by any stretch of the imagination, GRC nirvana. There will be many significant areas, from Department of Defense related federal requirements, to the extremely granular levels of security an increasingly networked global financial system requires, and many others.

But, I hope, and remain confident, that this will be the first in an ongoing series of steps towards ever-improving quality of governance, risk management and compliance standards, which will help cloud vendors and users alike.


Imran Anwar is founder of Internet email in Pakistan, co-founder and co-owner of the .PK ccTLD of Pakistan, and founder of the credit card industry there. As a New York based technology, media and business professional he is often seen and heard on global media like CNN, Fox News, Express TV, WWRL and many others. These are Imran's personal opinions and do not necessarily reflect those of any employer, employer's parent companies, clients, family members or other persons or organizations. Phew!



Technorati Tags: , , , , , , ,