Twitter breach revives cloud security fears
Some interest groups are urging Los Angeles to rethink its plan to implement Google Apps.
Computerworld - Last month's breach of a hosted Google Apps implementation used by Twitter Inc. has heightened fears in some quarters that cloud computing could pose significant security and privacy risks to users.
The Twitter breach gave a hacker access to confidential company documents via an employee's work Gmail account that had been hijacked through the password reset feature.
Shortly after the breach, some public interest groups and local law enforcement officials cited potential security concerns in calling on the city of Los Angeles to reconsider plans to replace its Novell GroupWise e-mail and Microsoft Office software with Google Inc.'s hosted e-mail and office productivity applications.
The $7.25 million migration project is set to begin later this year after its expected approval by the Los Angeles City Council. City officials have projected that the move to Google Apps will save about $13 million in software licensing and personnel costs over a five-year period.
Consumer Watchdog, an advocacy group based in Santa Monica, Calif., said the Twitter incident raises questions about whether "Google's cloud as offered provides adequate safeguards." In a letter to several Los Angeles city councilors, the group urged that city IT personnel first test Google Apps with a small group of users, rather than following the current plan of implementing it for 30,000 users by the end of this year.
"Before jumping into the Google deal, [the city council] needs to insist on appropriate guarantees -- for instance, substantial financial penalties in the event of any security breach," John Simpson, a Consumer Watchdog project manager, wrote in a blog post.
In a letter sent to Los Angeles Mayor Antonio Villaraigosa on July 16, the World Privacy Forum encouraged the city to move "slowly and cautiously" in implementing Google Apps, citing "considerable legal uncertainty about the status of data in a cloud computing environment."
Matt Glotzbach, director of product management for Google Enterprise, said the angst voiced about Google Apps and the Los Angeles project is based on incomplete information. "From what I know of the city's operation, this is a security upgrade," Glotzbach said. "Those who may be unfamiliar with cloud computing see this as a security risk simply because it is new and because it is something different."
- Securing Mobile App Data - Comparing Containers and App Wrappers Analysts agree that Mobile Device Management (MDM) is not enough when it comes to securing app data. Although it remains a critical component...
- PCI 3.0 Compliance In this white paper, learn how PCI-DSS 3.0 effects how you deploy and maintain PCI compliant networks using CradlePoint devices.
- Mitigating Security Risks at the Networks Edge This white paper provides strategies and best practices for distributed enterprises to protect their networks against vulnerabilities, threats, and malicious attacks.
- 5 Strategies for Modern Data Protection Read the five strategies for modern data protection that will not only help solve your current data management challenges but also ensure that...
- Business-driven data protection Setting up data protection infrastructures with your organizations' core mission or business in mind is key. In this webinar, the ARCserve team will...
- On-Demand Webinar: Mind the Gap! Watch the webinar featuring Bob Janssen, CTO and Co-Founder of RES Software, to start building a solid foundation for business and IT to... All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!