Bitbucket’s weekend troubles with Amazon’s cloud services are instructive, but don’t necessarily indicate a problem with cloud security.
The major lesson to learn from Bitbucket’s experience is don’t put all your bits in one bucket. The company, which hosts a Web-based coding environment, entrusted all its network to Amazon’s cloud services, either its EC2 computing resources or its EBS storage service.
Any business that is going to do that needs a plan B for when things go wrong as they did last weekend when Bitbucket apparently suffered a DDoS attack that took Bitbucket and Amazon about 20 hours to diagnose and fix. Meanwhile, customers of Bitbucket couldn’t work on their own projects because they couldn’t reach Bitbucket.
Beyond not having an alternative to Amazon, Bitbucket seems to have lacked a service contract that guaranteed rapid escalation of the problem to the appropriate level. Eventually with enough complaining from Bitbucket and some of its influential customers Amazon threw a security team at the problem and fixed it. But they really needed a formal agreement on how to escalate.
The problem also points out that despite the security offered by cloud providers, businesses that buy cloud services need to have effective monitoring and security of their own in place.
But the bottom line is that if a business is going to commit its whole business to the cloud, it needs to consider what happens when the cloud fails. It needs to have a real alternative that can keep the business running when the primary provider goes offline. As a wise network consultant says, SLAs give you someone to sue if something goes wrong, but they don’t prevent things from going wrong.




