Growing pains in the Cloud and Virtual Environments… Did someone check the security box too fast?
Virtual Environments have had their share of aches and pains, but at the end of July, it seems the Network Function Virtualization (NFV) and Cloud players are getting a bit of extra attention when it comes to security.(Originally published in 2016)

A Spike in Virtual Security Failures
While I am not sure if Black Hat Las Vegas kicking off at the end of the month is affecting this or not, it seems we have had a flurry of virtual environment related security problems. Everything from the Xen Hypervisor bug which can potentially let rogue system admins break out of their virtual boxes and play with the host systems (ouch) to a SwiftKey issue that appears to be syncing data such as email addresses and phone numbers with the wrong users. Um, I really don’t need Oscar in New Zealand’s email address!
Are We Moving Faster Than We Can Secure?
The sudden flurry of (expected?) secholy smokes-t nether of the virtual world make one wonder if adoption is outrunning the attention that is required to provide at least minimal levels of security. Protecting the privacy of customers and their Personally Identifiable Information (known as PII in the tech world) should be up at the top of the priority list, regardless of “core” business drivers. (queue screaming from marketing here)
Virtual environments and the “Cloud” have many benefits but one could argue that putting all ones eggs in a single “virtual” basket that the weaver is frantically trying to finish, might be just raising the risk bar a bit too high.
Question: Would you buy a new car knowing that the manufacturer was still trying to get the door locks working correctly and the brakes to engage when the pedal was actually being pushed?
I have been thinking that we need to reconsider our approach and take appropriate measures to both limit risk exposure, and to incorporate security in every step of architecture of, and deploying these, and other “new tech,” environments. Virtualized technologies are relatively new and many companies are transitioning rapidly, many critical parts of these solutions (Xen’s Hypervisor for example) are still being taken for a road-test of sorts-and there is plenty of opportunity for things to slip through the cracks when leveraging virtual environments. With the industry fluidity and movement such as SwiftKey recently being bought by MS for 250M, stability in processes will increasingly affect security goals in an adverse way. As with any major project, those entertaining the move to a virtual environment should carefully weigh all the aspects before taking the proverbial leap.
Caution Before Adopting
There was an interesting article on The Register the recently which concerned blockchains and their maturity level. It is a well spent few minutes to peruse the
article. What I got out of the article is that we are not quite ready for prime time and we should tread carefully for the time being.
Being somewhat involved in the subject of security and virtual environments, I take the view that we should not repel such new technologies but we should experiment with them thoroughly and when deploying in real world (production) environments, that we should do so cautiously. Virtual Environments can make life much easier for us, but they can also expose a much larger attack surface (and the associated compromise of significantly more sensitive information) than would normally be found in a non virtual environment. An extra level of diligence should always be applied as a result.
Consulting: Need independent analysis or security support? See AI & Cybersecurity Consulting.
