Category Archives: Technology
10 Mistakes You Make When You Try To Build a Private Cloud
VentureBeat recently ran a great article on 5 Mistakes You’re Making When You Try to Build a Private Cloud that did a great job of covering 5 mistakes you make, but why stop there? SI can easily come up with 10 mistakes, more if it gives the issue a second thought. So, since some of you still don’t believe that The Cloud is Filled with Hail, let’s review the VentureBeat 5 and throw 5 more into the mix to see if that’s enough to convince you that The Cloud is Not a Magic Mirror — especially when you take a do-it-yourself approach!
VentureBeat’s 5 Mistakes of a Private Cloud are:
1. You believe the cloud will solve all your problems.
With so many vendors touting it, you believe that a cloud must be the answer, so why not control your own? There are a host of reasons, including those that will be discussed in response to the other wrong assumptions, but the most important thing to remember is that not all applications are good candidates for the cloud. Applications that are intermittent, that run full tilt, or that spike unexpectedly are not always good cloud candidates — public or private.
2. You think everyone will automatically love the idea.
You keep hearing that clouds bring agility, adaptability, and actionable data — so you think that you can convince everyone else to fall in love with the cloud too because you believe that these are reasons to fall in love with the cloud. A cloud is as adaptable as the software that drives it, as actionable as the data you can get into it, and as agile as your organization — if it takes 3 months to get a product to market using the best processes you can come up with, it takes 3 months to get that product to market — cloud or no cloud.
3. You think it’s cool.
Clouds aren’t cool (although the rain they bring may cool you off). And unless you are in the business of selling “cool” technology (i.e. private clouds to suckers who buy private clouds), the last thing you should be basing a business decision on is the “cool” factor. You buy technology to solve your problems, not because it’s cool.
4. You think you will succeed in boiling the ocean.
A private cloud is a huge IT project similar to trying to replace 3 ERPs across your global organization that have been entrenched for 10 years across 3 continents in one fell swoop while trying to add 4 modules you never had before. It’s like trying to boil the ocean with a single giant magnifying glass — brave, maybe even visionary, but ultimately stupid.
5. You think your plan will fit the organization.
The typical private cloud relies on converged infrastructure (CI) stacks which break down the typical organization walls of application teams, server teams, network teams, and storage teams. How many Global 3000 organizations have one single version of the truth across the enterprise? Maybe the few dozen organizations that successfully achieved enterprise wide deployments of SAP and Oracle?
That’s just the beginning. Here are 5 more mistakes courtesy of SI:
6. You think a private cloud will be cheaper than a public cloud.
You might think that a cloud is a fluffy magic box that can be obtained with a handful of magic beans that you can get by trading a simple cow, but that’s about as far from reality as you can get. Clouds require hardware, software, dedicated network connectivity, and power. Lots of power. You will need backup generators in addition to a wall of UPS units (to keep the machines humming until the generators kick in), multiple fibre connections, racks of machines and storage area networks, and a lot of specialized software. And, instead of sharing the cost, you get to pay for it all — as well as the staff to build it and maintain it 100% — 24/7/365.
7. You think all modern technology was built for the cloud.
A lot of software is, but not all — and chances are that a lot of the software you are using, even if still under maintenance, was not built for the cloud. So, you’ll have to update your current software and migrate your current data stores while you are at it.
8. You think it is the best way to interact with your trading partners and the private clouds you wrongly assume they have.
The cloud is connective, but only if it is shared. Otherwise, it’s just one massive local area network that needs to talk with other massive local area networks used by your trading partners. Clouds don’t create connectivity – data interchange standards do, and you don’t need clouds for that!
9. You think you can secure it better than the experts.
Hi Ho, Hi Ho.
It’s off to work we go!
We block the ports and tune the firewall
In our ‘Net the whole day through
We block the ports and tune the firewall
It’s what we like to do
It ain’t no trick
To lock down quick
If ya block the port
With a sniffer on a ‘NIC
In the ‘Net …
And you can block every port, patch every firewall, and sniff every ‘NIC, but the reality is, your network is only as secure as the weakest link — which is probably the software you’re using and the ports you need to have open. Which you don’t know how to protect because your IT staff is struggling to patch your firewall, scan the ports, and upgrade SSL before the heartbleed bug bleeds you dry of your corporate secrets. When it comes to security, you need true security experts — and you’re not going to have them in house.
10. You think the cloud can actually be secured.
The only way to truly secure a network is to unplug it. So if you think you have a hope in Hades of securing your private cloud …
Commercial Spam Turns 20 Today!
Some other time, some other place
We might not have been here, with egg on our face
I just wanna tell you, made up my mind
You know I can’t help the way I feel inside
Oh, this heart’s on fire
Right from the start, it’s been burning with rage
Oh, this heart’s on fire
One thing buddy, spam fills it with rampage!
And 20 years ago today, Laurence Canter and Martha Siegel unleashed the “Green Card” spam upon the world. While this was not the first instance of Usenet spam, it was the first instance of commercial Usenet spam and, quoting Wikipedia, its unapologetic authors are seen as having set the precedent for the modern global practice of spamming.
Canter and Siegel sent their advertisement, with the subject “Green Card Lottery – Final One?”, to at least 5,500 Usenet discussion groups, which was a huge number at the time, posting it as a separate posting in each newsgroup so a reader would see it in every group they read. Their internet service provider, Internet Direct, received so many complaints that its mail servers crashed repeatedly for the next two days! You have to remember, this was back in the time of dial-up and the highest speed modems available at that time were fax-speed 14.4K modems, with most people still on 2,400 baud modems! But this effort, and their subsequent efforts through Cybersell, which was a “spam-for-hire” company, ushered in the age of spam that we are still dealing with to this day.
You Can Have Your Google Chauffeur. I’ll Choose Good Ol’ Alfred Every Day of the Week!
For those of you who thought the doctor was needlessly calling #badwolf last Sunday in response to the automotive industry’s push for autonomous automobiles, SI would like to point out this recent BBC News article stating that Toyota is to recall 1.9 Million Prius hybrids.
Why is Toyota recalling 1.9 Million Prius hybrids? A software fault that may cause the vehicle to slow down suddenly. To date it has identified more than 400 reports of the problem, with the bulk of them occurring in (the heavily congested streets and highways of) Japan and North America. According to Toyota in limited cases, the hybrid system might shut down and the vehicle will stop, perhaps while being driven.
In other words, all a hacker has to do to cause multiple fatal multi-car pileups is hack the OnStar network and send a signal to all Prius’ vehicles to execute that specific part of the code. They don’t even have to break the OS and figure out how to craft a small virus that will hijack the control system or execute a dangerous set of commands — the hacker just has to send a signal telling the OS to execute the set of commands already there.
Now, presumably, this would (hopefully) result in the brake lights being triggered and the outcome may not be as deadly as it would be otherwise, but what about the other 99 Million Plus lines of code. How many similarly dangerous, untested, and, as-yet, unexecuted code sequences are also in the Prius? And every other electronically controlled car on the road?
They’ve yet to release a personal OS that isn’t riddled with more holes than there are potholes in Canada’s winter roads*1! I’m all for technological advance, but until we figure out how to write more bullet-proof, and secure, operating systems, let’s keep the OS out of the car and on the desktop where it belongs.
Now if you’ll excuse me, I have to go help LOLCat tell some meddling kids to get off my lawn!
*1 A slice of swiss cheese is quite solid in comparison!
The Storm Clouds Are Coming!
Fifteen years ago, enterprise software was installed on-premise and managed locally. This required organizations with no knowledge of IT or IT management to create IT departments to manage servers and the software services that ran on them. For an organization that didn’t use software in it’s daily operations — such as a manufacturing organization that used manual production lines, an advertising agency that deals in existential image and not physical product, or a real-estate agency that only has to take listings and take cheques — it was an expensive proposition.
Then came the Application Service Providers, better known as ASPs. Using the power of the internet, these software solution providers built their own data centres and hosted the solution for their customers on dedicated machines in their own data centres. However, this solution was not optimal either, as the organization was not only paying for machines, energy, and administrators to run the software, but also paying for these through a thirdparty that added overhead and markup.
This provided an opportunity for more enterprising software delivery organizations that were able to build their applications to be multi-tenant and host multiple clients on the same platform. This reduced the number of machines, kilowatts, and system administrators that were required and thus reduced the overall operating cost. This allowed this new breed of Software-as-a-Service (SaaS) vendor to take business away from the ASPs and advance the state of the art.
But this wasn’t the end. New enterprising software delivery organizations, who realized that their expertise was software and not data centre management, decided that they could do even better if they designed multi-tenant Software-as-a-Service solutions that could be run on someone else’s platform. This would bring more economies of scale into play as not only could multiple solutions could be run on the same platform, but the platform provider could be replaced by another platform provider with a lower-cost at any time. Enter the Cloud, which, like a real cloud is ephemeral, suspended in space, and, in some cases, full of security holes.
Cloud services are ephemeral as any specific instantiation of cloud services last as long as the company behind it has the means and the desire to continue supporting the cloud services. Cloud services are suspended in space since the instantiations may move over time as the service owners switch to lower-cost and/or more secure data centres. And, with the recent revelations on the PRISM program, the cloud is full of security holes to the point where the EU Parliament has called for suspension of the multi-billion ‘Safe-Harbour’ deal over NSA spying because some cloud providers don’t, either because they don’t have the expertise or won’t spend the money, secure their part of the cloud properly.
As a result, supply chains are exposed to additional risks of disruption (if a cloud provider unplugs overnight), security breaches (as some platforms are significantly less secure than others), and privacy risks (as some governments claim the right to all data on servers on their shore that is not associated with citizens or entities of that country or that might pose a security risk under acts like the US Patriot Act).
And this is only one of 14 significant threats to the supply chain in 2014. Would you like to know what the other 13 are? If so, download SI’s latest white paper on the Top Ten Transitions To Tackle in 2014 to Tame the Tolls, sponsored by BravoSolution. (Registration Required) Or, you could just wait and be surprised as the other 13, riding on black swans, one by one, strike at each full moon. Your call.
