Today is: Tuesday, 6th January 2009
Log in
Technology, Web Development and Saltwater Fly Fishing, not in that order.
- The online home for Mark Cahill, and indeed, all things Cahill!
- About
- Photo Gallery
- Subscribe
The Dark Side of Cloud Computing
We’ve all done it. Try to email something to a friend and Outlook, or whatever mail client we use accidentally selects a different contact to send to. It’s not such a big problem when you’re sending pictures of the baby, or directions to the weekend barbeque, but what happens when you accidentally send sensitive information to the wrong person, like a journalist.
The problem is utterly compounded when you give accidentally give access to your information sitting out in the cloud. Things like sharing a Google Doc with the wrong person, or giving access to sensitive Google Analytics info with a journalist. Especially one who works for a competing media giant.
That’s exactly what happened at Community Newspaper Holdings recently. Apparently someone meant to share Google Analytics access for all their sites with a staffer named Denise Gallagher but instead shared access with David F. Gallagher, who writes the tech blog for The New York Times. If you were the person who gave access to the Times, I can sum up your thoughts on seeing this headline: “I’m in Your Google Docs, Reading Your Spreadsheets.” That thought has got to be “my career is over.”
There was a time when it would have taken a fair amount of criminal activity to get access to this much information about a company’s internal workings and Web site performance. Now an employee can accidentally drop it into the lap of a random outsider without even knowing that anything is amiss. That’s the power of cloud computing at work.
Most of the discussion about the security of online applications revolves around whether or not you can trust Google and its competitors to protect your data. In this case, CNHI needed to be protected from its own employee. Google could help with this by, for example, flashing a warning before you share a document with a person you have not exchanged e-mail with in Gmail. But in the end, security requires careful typing — and perhaps some careful decisions about whether some documents would be better left behind the corporate firewall.
Here’s the issue, as we all make more and more use of Cloud Computing apps, like Google Docs, like Google Analytics, we’re taking huge risks with not only our company data, but our professional lives. This is the one big failing that we tend to miss, the potential for error is so great, that it’s really not a matter of if mistakes will happen, it’s a matter of how many, and how severe.
What Google has missed by forcing us to use gmail addresses as the common login parameter for these apps is that for business security reasons, we must be able to authenticate against our own internal, authoritative systems. It’s wrong to expect business to maintain customer access in potentially hundreds of cloud apps, instead they need to open a bridge to the business so that one single point of authentication can be maintained. In this manner, it’s easy to add someone, and more importantly, easy to remove them if you need to.
This is a huge problem right now in business. I know of people who have left previous employers and are still having company email, including staff only stuff and management level group email, forwarded to them at their Gmail accounts. I know of situations where a year or two later, users still have access to external systems like Webex, etc. Is it all inept management? No, the problem is that the more logins you must manage, the more likely you’re going to forget something. And once in a while, that something is going to be really, really important.
Tags: cloud computing, community newspaper holdings, google analytics, google docs, new york times, security
About Us
I'm Mark Cahill - Online community developer and content management wonk since 1995. I'm interested in new media, communities and social networking, and love saltwater fly fishing. For a longer version, you can read my full about us page.
I am mncahill on Twitter
Email me at allthingscahill at gmail
My Facebook Page
![]() |
Subscribe RSS |
| Subscribe Email |
Tag Cloud
apple Automattic Broadcast Media chain of lights chris anderson cnn Dave Brubeck david churbuck facebook geek.com google iphone jason calacanis layoffs lenovo leo laporte linkedin long tail Music Video newspapers new york times niche communities niche social network olympics online community building orange county register print media Red Sox reel-time.com reel time safari Saltwater Fly Fishing signal to noise ratio social media Social Networking Striped Bass Sutton Sutton Chain of Lights Sutton Ma twitter Web 2.0 Web Design Wordpress Wordpress 2.5 wordpress 2.7Categories
On Twitter - mncahill
- A Seal sneaks into the Fish Hatchery in Sandwich MA for a trout buffet. Photos http://poprl.com/BTK 44 mins ago
- @swoodruff You will not only burn your feeds, you'll burn them onto your muffins! in reply to swoodruff 1 hr ago
- @technosailor WP Roles are very much in need of revision. They are Stalinist in their enforcement today...also a little more workflow in reply to technosailor 1 hr ago
- @swoodruff The new iToaster had them beat... http://twitpic.com/107zu in reply to swoodruff 1 hr ago
- @chipgriffin Glad to hear it! I bet they all stood the test of time...;-) in reply to chipgriffin 1 hr ago
- More updates...
My del.icio.us
Recent Comments
- Mark Cahill: Excellent point - it is the Internet A-List types that are a...
- Esteban: I partially agree. Online big egos are at risk, personal bra...
- Kim Woodbridge: Thanks Mark! I've had a rough week and that really means a ...
- Esteban: Shark Jumping post was epic! and now we see the word has spr...
- Sunny: Wow looks gorgeous.. Freezing let gorgeous! :)...
- Mark Cahill: I really do wonder if Twitter really ever reach mass adoptio...
- Eric Guerin: Thanks for the mention, I think we may be the ONLY two resid...
28 Aug 08 | 







