Cloud services raise security, privacy concerns, experts say

Changes in U.S. law and vendor agreements may still be needed to protect privacy, panelists say

A move toward more and more services in the cloud is inevitable, but vendors still need to focus on security, and the U.S. government needs to rewrite privacy laws to protect cloud customers, a group of experts said Tuesday.

Cloud computing will offer many benefits, including remote access to data, remote collaboration and reduced IT costs, said Greg Nojeim, senior counsel for the Center for Democracy and Technology. But cloud vendors, customers and U.S. policy makers still have "a lot of questions to work through," he said at a forum on cloud security and privacy at The Brookings Institution in Washington, D.C.

Nojeim called on the U.S. Congress to update the 24-year-old Electronic Communications Privacy Act (ECPA), which gives data stored on personal computers greater protection from law enforcement searches than data stored with third-party services. Law enforcement officials typically need to get a court-ordered warrant to search the hard drive on a PC, but need only a prosecutor- or investigator-issued subpoena to access data stored in the cloud, he said.

"The law shouldn't discriminate between the privacy of something I store locally and something I store remotely," he said.

Law enforcement agencies weren't represented on the Brookings panel, but the U.S. Department of Justice has argued that quick access to information by law enforcement agencies can stop crime and, in some cases, save lives.

Beyond legal questions, cloud vendors have several security issues to face, other panelists said. The security goals of customers may not match the priorities of cloud providers, said Alan Friedman, research director for the Center for Technology Innovation at Brookings and co-author of a new paper on cloud security. In addition, data privacy laws differ significantly between nations, and some U.S. cities have demanded that their providers store data only in the U.S. for security reasons, even though the European Union has stronger privacy protections for cloud users, he said.

U.S. government entities are "very concerned about other nation[s] accessing data, but still we're reluctant to adopt strong regulations, as the EU currently has," he said.

Friedman and Marjory Blumenthal, associate provost for academic affairs at Georgetown University and a longtime technology policy expert, also raised concerns about ambiguity in cloud computing agreements between vendors and customers. There's little legal precedence on enforcing promises made in the agreements, Friedman said.

Many cloud providers so far have claimed they are not responsible for the data stored on their service, Blumenthal said. The use of virtualization in cloud computing environments could also lead to data leaks between customers if the virtualization isn't done correctly, she said, and cloud providers will likely become tempting targets for cybercriminals.

"It's reasonable to expect that providers will be increasingly targeted by organized crime," she said.

But vendors will address many of the concerns about cloud computing because of increasing competition, said Harry Wingo, senior policy counsel at Google, a provider of cloud-based services. Vendors should be transparent with customers about how their data is stored and used, and they should allow customers to easily transport their data to other services, he said, but as long as those things happen, competition will drive improvements in cloud services.

Cloud vendors are beginning to look at new encryption and fraud detection techniques, Friedman said.

"Competition is going to allow a race to the top for security," he added. "We'd like to see security as a differentiated service."

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's e-mail address is grant_gross@idg.com.

Tags Harry WingoThe Brookings InstitutionMarjory Blumenthaldata protectioninternetGreg Nojeimcloud computingprivacyGeorgetown UniversityGoogleAlan Friedmansecuritydata breachCenter for Democracy and Technology

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Grant Gross

IDG News Service

Comments

Comments are now closed.

Most Popular Reviews

Follow Us

Best Deals on GoodGearGuide

Shopping.com

Latest News Articles

Resources

GGG Evaluation Team

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Steph Mundell

LIFEBOOK UH574

The Fujitsu LifeBook UH574 allowed for great mobility without being obnoxiously heavy or clunky. Its twelve hours of battery life did not disappoint.

Andrew Mitsi

STYLISTIC Q702

The screen was particularly good. It is bright and visible from most angles, however heat is an issue, particularly around the Windows button on the front, and on the back where the battery housing is located.

Simon Harriott

STYLISTIC Q702

My first impression after unboxing the Q702 is that it is a nice looking unit. Styling is somewhat minimalist but very effective. The tablet part, once detached, has a nice weight, and no buttons or switches are located in awkward or intrusive positions.

Latest Jobs

Shopping.com

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?