Wednesday, August 12, 2009

Cloud Insecurity

Interesting article about Clive Peeters - an Australian company - and how they have been left reeling by $20m sting by their payroll manager.
...she admitted to using a loophole in the company's internet banking with National Australia Bank to steal from the company.
What this reminded me of was a customer focus group about federation that I did while I was at Microsoft. I'm not sure if this is the exact words that the CIO of a company used during the meeting but it is close enough:
Why would I want to use federation in my business when I can't even trust my own staff not to write down their passwords and leave them stuck to their monitors or to even log off their workstations at night?
While the article I reference isn't exactly related to cloud computing it does highlight the fact that we still have a long way to go with respect to security. Here's another article that seems appropriate to the discussion: Why cloud security is only as strong as your weakest password (and what you can do about it)

