Cloud Computing
News
- Pew/Elon Study: Cloud Computing Will Expand, Security and Privacy Issues Must be Addressed: According a recent Pew Internet and Elon University survey , most technology experts believe that the next decade will bring increased reliance on internet-based applications and cloud computing. The experts and social analysts surveyed also predicted greater use of mobile devices, with an accompanying reduction in general purpose computing. The survey found that the cloud computing brings considerable privacy and security risks. EPIC has a complaint pending before the Federal Trade Commission on Cloud Computing and Privacy. For more information, see EPIC Cloud Computing. (Jun. 11, 2010)
- Congress Pursues Investigation of Google and Facebook's Business Practices: Following similar letters from other Congressional leaders, the head of the House Judiciary Committee has asked Google Inc. and Facebook to cooperate with government inquiries into privacy practices at both companies. Rep. Conyers (D-MI) noted that Google's collection of user data "may be the subject of federal and state investigations" and asked Google to retain the data until "such time as review of this matter is complete." Rep. Conyers also asked Facebook to provide a detailed explanation regarding its collection and sharing of user information. The House Judiciary Committee is expected to hold hearings on electronic privacy later this year. For more information, see EPIC: Facebook Privacy, EPIC: In re Facebook II, and EPIC: Search Engine Privacy. (Jun. 1, 2010)
- Congress Urges FTC to Investigate Google Following Revelation that "Street View" Scarfed Wi-Fi Data: Congressmen Joe Barton (R-TX) and Edward Markey (D-MA) wrote to FTC Chairman Liebowitz about Google's collection of consumer's private Wi-Fi transmissions. The House members asked the FTC Chairman to investigate whether Google's actions violate federal privacy laws or consumer protection laws. Google has admitted to collecting email and internet surfing data, but has not clarified the extent or nature of the data collection. The letter from Congress follows an investigation in Europe which revealed that Google's "Street View" vehicles in 30 countries collected not only digital images, but also data transmitted on private wireless networks. EPIC has several privacy complaints pending at the FTC, including one on Cloud Computing. (May. 19, 2010)
- FCC Release National Broadband Plan, Privacy Strategy Unclear: The Federal Communications Commission (FCC) released its National Broadband Plan today. The FCC notes that “many users are increasingly concerned about their lack of control over sensitive personal data" and warns that "Innovation will suffer if a lack of trust exists between users and entities with which they interact over the internet.” The FCC makes several recommendations, but there is no clear plan to address growing concerns about cloud computing, smart grids and unfair and deceptive trade practices. Last year, EPIC urged the FCC to develop a comprehensive strategy for online privacy as part of the national broadband strategy. (Mar. 17, 2010)
- EPIC Recommends Effective Consumer Privacy Standards, Calls Notice and Choice a "Failed Experiment": At the third FTC Privacy Roundtable, EPIC senior counsel John Verdi will recommend that the Commission push forward with effective and meaningful privacy safeguards for American consumers. Mr. Verdi will say that the "notice and choice" approach has failed, and will recommend that the FTC enforce Fair Information Practices, such as the OECD Privacy Guidelines. The discussion can be viewed via webcast. Additional information on the FTC roundtable event can be found here. For more information, see EPIC In re Google Buzz, EPIC In re Facebook, and EPIC In re Google and Cloud Computing. (Mar. 17, 2010)
- EPIC Seeks Records on Google-NSA Relationship: Today EPIC filed a Freedom of Information Act request with the National Security Agency, seeking records regarding the relationship between Google and the NSA. The press reported that Google and the NSA have entered into a partnership following a recent hacker attack on Google originating from China. The EPIC FOIA request also seeks NSA communications with Google regarding Google's failure to encrypt Gmail and cloud computing services. In March 2009, EPIC filed a complaint with the Federal Trade Commission urging it to investigate the adequacy of Google's cloud computing privacy and security safeguards. Today EPIC also filed a lawsuit against the National Security Agency and the National Security Council, seeking a key document governing national cybersecurity policy. For more information, see EPIC FOIA Litigation and EPIC Cloud Computing. (Feb. 4, 2010)
- EPIC Urges FTC to Protect Users' Privacy On Cloud Computing and Social Networking Services: EPIC submitted comments to the FTC prior to the agency’s second privacy roundtable. EPIC warned of the ongoing privacy risks associated with cloud computing and social networking privacy, highlighting the Google cloud computing complaint and Facebook privacy complaint filed by EPIC in 2009. The comments note that the FTC has failed to take any meaningful action with respect to either complaint, demonstrating the Commission's “lack of leadership and technical expertise.” EPIC's comments also draw attention to the success of international privacy initiatives, in hopes of encouraging the FTC to take meaningful action to protect American consumers. For more information, see EPIC: Cloud Computing and EPIC: Social Networking Privacy. (Jan. 28, 2010)
- FTC Tells FCC it is Pursuing EPIC's Cloud Computing Complaint: The Federal Trade Commission is urging the Federal Communications Commission to consider the privacy implications of cloud computing in formulating the National Broadband Plan, due to Congress next month. The FTC interest into cloud computing was prompted by an EPIC complaint to the FTC in March 2009, in which EPIC described numerous privacy and security risk involving cloud-based applications. A subsequent letter from computer researchers and security experts supported EPIC's findings. For more information, see EPIC: Cloud Computing. (Jan. 6, 2010)
- ENISA Report Examines Cloud Computing and Privacy: The European Network and Information Security Agency has released a new report on Cloud Computing. The ENISA report recommends that European officials determine the application of data protection laws to cloud computing services. The report also considers whether personal data may be transferred to countries lacking adequate privacy protection, whether customers should be notified of data breaches, and rules concerning law enforcement access to private data. Earlier this year, EPIC filed a complaint with the Federal Trade Commission, urging the Commission to examine the adequacy of privacy safeguards for cloud computing services. A subsequent letter by computer researchers, addressed to Google CEO Eric Schmidt, raised similar concerns. See EPIC Cloud Computing. (Nov. 25, 2009)
- Administration Announces Cloud Computing Initiative, but Privacy Umbrella Missing: Chief Information Officer Vivek Kundra announced the launch of “Apps.gov”, a website where federal agencies can obtain cloud-based IT services. The initiative is aimed at "lowering the cost of government operations while driving innovation." Currently, the administration's main goal is to increase the size and scale of cloud computing, but key concerns, such as security and privacy, have received little attention. In March, EPIC filed a complaint with the FTC urging the agency to open and investigation into Cloud Computing services, such as Google Docs, to determine "the adequacy of the privacy and security safeguards." Subsequently, thirty-eight computer security researchers and privacy academics sent a letter to Google's CEO, asking Google to uphold privacy promises made to users of Google Cloud Computing services. The FTC investigation is ongoing; no response has been received from Google. For more information, see EPIC's page on “Cloud Computing”. (Sep. 17, 2009)
Introduction
Cloud Computing can be thought of as a way to make the world of computer resources seamlessly scalable. "Cloud Computing Services" can involve "a software and server framework (usually based on virtualization)" that uses "many servers for a single software-as-a-service style application or to host many such applications on a few servers." Cloud Computing Services are an emerging network architecture where applications reside on third party servers, managed by private firms that provide remote access through web-based devices. Customers generally do not own the infrastructure. This model of service delivery is in contrast to an architecture in which data and applications typically reside on servers or computers within the control of the end user.
Users lose control of their information when they place applications, and their data files, on centralized servers. Critical and sometimes sensitive information that was once safely stored on personal computers now resides on the servers of online companies. Cloud Computing Services may mean that both access to the application and our data will be at risk by placing both in the hands of a third party. Data hostage scenarios are not hard to image, when it is vital that a user gain access to online information, but the data holder refuses that access without first receiving a payment or other compensation.
Some Cloud Computing Services use encryption, by default, to "respect individual privacy" and "provide users with the ability to fully control and customize their online experience." In addition, some Cloud Computing Services state, as a "key principle" that "users own their data, and have complete control over its use. Users need to explicitly enable third parties to access their data." However, other cloud computing services store data in plain text.
New cloud computer services are offering to store computer information for users, to assure that data is not lost, but little is said about the confidentiality or privacy of the information placed under the control of "cloud computing" service providers. Legal rights and regulatory authority for the protection of the privacy of cloud computing users are not well defined. There are many risks for cloud computing customers that should be explored and new legislative and regulatory frameworks developed to assure the confidentiality and privacy of data. A survey of Internet users, published in March 2009, found that 35% believed that their privacy had been violated at some point over the previous year.
Cloud computing may come in three forms:
1. Software as service or SaaS is one type of cloud computing when an organization outsources its IT assets, such as when an organization rents computing capacity for intensive computations that are beyond the capabilities of their on-site computer hardware. Peer-to-peer networks like BitTorrent and Skype ship data to servers via the Internet for processing or storage purposes. There are also desktop application services that remove the work from personal computers to remote servers hosted by cloud computing service providers such as Google Apps and Zoho Office.
2. Capacity Cloud Computing services that provide a single service to many users. Types of this kind of Cloud Computing are Amazon.com, Health IT services, and Wiki document hosting platforms. These Cloud Computing service providers may also engage customers by offering the equivalent of data centers to support large applications or manipulation of information. The customer may not be able to purchase high-end hardware or have a need to acquire specialized software for a project, but can cost effectively rent these services from an Internet cloud vendor.
3. Software cloud computing services is transparent to consumers who are aware of and opt-into using. For example, Health Information Services, Gmail, AOL, and Yahoo e-mail are free software as email products. The user's emails and email client software are stored on remote servers that can be accessed from any computer connected to the World Wide Web. This model is being embraced by numerous software providers and is also called utility computing because typically one pays a monthly fee to have the benefit of the e-mail service provided by a single vendor.
Background
Cloud computing or remote computing services have matured over recent years, but its underlying concepts are not new. The earliest computing operations allowed multiple users to bring work projects, usually in the form of data encoded onto punch cards, magnetic tapes, or floppy disks to a central stand-alone computer for processing. These stand-alone computers could only perform one job or task at a time. The development of operating systems allowed stand-alone computers to perform multiple functions simultaneously.
The "Cloud" refers to data, processing power or software being stored on remote servers made accessible by the Internet (the cloud) as opposed to being stored on one's own computers. Internet computer users have engaged in cloud computing arrangements through e-mail providers, wiki applications, and online tax preparation as well as digital filing services. This approach means that end users do not own the technology that will hold their information and depend on the hardware and software resources of the cloud computing service provider. The data owners must also rely on the telecommunications infrastructure that will act as delivery and retrieval pathways for the flow of data to and from the cloud.
The emergence of cloud computing services is structured around a re-imagining of the relationship between technology and end users. The further users are away from the underlying technology that they rely upon, the more dependent the relations may become. The move toward computing resources as a service to be provided by remote sources with greater access to unbounded computing power presents some attraction to computer users with limited resources and a growing need for information services. Once an end user adopts a cloud computing arrangement it may be difficult to move back to a personal computing based platform for data services.
Types of Cloud Computing Services
Examples of the some of the types of online cloud computing include database and backup services. Amazon Simple Storage Service (Amazon S3) and Amazon Web Services (AWS) offers a range of Cloud Computing services that allow users to "securely" store, and manage a wide range of data types.
Amazon S3 promotes itself as reliable, but its service level agreement states that the company can terminate the service.

AWS incorporate identity, payment, database, messaging, and other services. However, the terms of service states "AWS reserves the right to refuse service, terminate accounts, remove or edit content in its sole discretion." Further, the AWS terms and conditions' "Disclaimer of Warranties and Limitations of Liability," state that:
"AWS DOES NOT WARRANT THAT THIS SITE; INFORMATION, CONTENT, MATERIALS, PRODUCTS (INCLUDING ANY SOFTWARE) OR SERVICES INCLUDED ON OR OTHERWISE MADE AVAILABLE TO YOU THROUGH THIS SITE; ITS SERVERS; OR E-MAIL SENT FROM AWS ARE FREE OF VIRUSES OR OTHER HARMFUL COMPONENTS. AWS WILL NOT BE LIABLE FOR ANY DAMAGES OF ANY KIND ARISING FROM THE USE OF THIS SITE OR FROM ANY INFORMATION, CONTENT, MATERIALS, PRODUCTS (INCLUDING SOFTWARE) OR SERVICES INCLUDED ON OR OTHERWISE MADE AVAILABLE TO YOU THROUGH THIS SITE, INCLUDING, BUT NOT LIMITED TO DIRECT, INDIRECT, INCIDENTAL, PUNITIVE, AND CONSEQUENTIAL DAMAGES, UNLESS OTHERWISE SPECIFIED IN WRITING. CERTAIN STATE LAWS DO NOT ALLOW LIMITATIONS ON IMPLIED WARRANTIES OR THE EXCLUSION OR LIMITATION OF CERTAIN DAMAGES. IF THESE LAWS APPLY TO YOU, SOME OR ALL OF THE ABOVE DISCLAIMERS, EXCLUSIONS, OR LIMITATIONS MAY NOT APPLY TO YOU, AND YOU MIGHT HAVE ADDITIONAL RIGHTS."
As further protection for itself, Amazon limits all legal actions that may arise over its Cloud Computing services to King County, Washington, where the company is located.
Another Cloud Computing service provider Mozy.com offers users cloud computing services to backup photographs, documents, accounting records, or any information that is stored on a personal computer. The service reserves broad rights to "at any time to modify, suspend, or discontinue providing the Service or any part thereof in its sole discretion with or without notice."

The Decho Corporation operates Mozy.com, MozyPro.com and Decho.com. The company considers signing up for the service as an agreement of the terms. The customer may end the agreement by "destroying the Software and closing your account," but it does not address what happens to the information that remains in the hands of the company. Closing an account does not mean that information collected or stored on the service will be removed.

The company defines personal "as any data from which it is practical to directly determine the identity of an individual." Further, under the terms and conditions users are told, "You agree to indemnify, defend, and hold harmless Decho and its suppliers from any and all loss, cost, liability, and expense arising from or related to your data, your use of the Service..."

Medical information services, such as WebMD provides tools to users that allow them to establish medical information accounts that can be used to record details regarding health conditions, symptoms, medications, search for medical professionals, and details about the type of medical advice sought.

WebMD's Terms and Conditions of Use, state that information provided to them by e-mail, blog posting, up-loading photos or video, or submitting information to "Public Areas," this information becomes the property of WebMD.

Although federal law allows for patient record privacy though the Health Insurance Portability Protection Act (HIPPA), the records created by WebMD and other health cloud computing services are not covered by HIPPA. WebMD states in its Terms and Conditions of Use that the company will not be liable for any damages.

Other Issues
Banking
Consumers are being asked to trust their personal and household financial information to cloud computing service providers.


E-mail service providers, such as America-on-Line, Yahoo, MSN, Hotmail, and Gmail provide cloud computing e-mail service to users. E-mail cloud computing service providers may allow secondary uses for e-mail communications. These uses may relate to advertising uses that the user agrees to but may not seek the consent of e-mail recipients. These services may also have unlimited data retention policies, or stated polices may change without notice.
Each of the relationships outlined also created new legal questions that have yet to be answered by model legislation or government regulation that addresses the rights of consumers.
How Did We Get Here
In 1969, the most significant advancement in remote computing communications technology began as an experimental project of the Department of Defense's Advance Research Projects Agency called ARPnet. The project's goal was to expand the distances that computers could reliably communicate. At the time the project was undertaken the cost of a computer was very expensive and for this reason the overwhelming majority of computer ownership was restricted to government agencies, educational institutions, and major corporations. The technology was not as fast as today's computing systems, which meant that the work that computers could perform such as calculations, sorting large data sets, or generating reports could tie up systems for hours, days or in some cases weeks. The ARPnet project sought to create a platform that would allow distributed users to share their valuable computing resources and collaborate on documents. There was no need to limit access to the ARPnet because there were so few mainframe computers in use at the time.
The next phase of the project sought to distinguish one computing system from another as they worked within the ARPnet computer remote communications project. The solution was the first application of a domain name system, which is designed to identify computers sharing a single network. Today, computers using the Internet are assigned Internet protocol (IP) addresses so that they have a unique identity while communicating online.
As the number ARPnet networked computers grew it was evident that a method of keeping track of them was necessary. This prompted the development of the Transmission Control Protocol/Internet Protocol (TCP/IP). A version of this protocol is still in use as the Internet's host-networking communication traffic management system. In 1983, the ARPnet was divided into two networks: MILNET, the unclassified Defense Data Network and the ARPANET. The term "Internet" was used to refer to the entire network. In 1988, the Defense Department ended the ARPANET project.
Much of computing in the 1960s-1980s was limited to text-based documents. By the early 1990s, the majority of TCP/IP registrations were coming from academic institutions. In 1993, there were approximately 7,500 unique Internet domain name registrations. The National Science Foundation (NSF) was asked to take on the responsibility of managing domain name registrations because this necessary function continued to increase in difficulty. The NSF developed a new domain name management system to deal with the growing number of computers on the Internet. The new method continued to rely on the TCP/IP protocol and created partitions based on categories for registered computer networks, which is best known to today's Internet users by the ending extensions found in natural name addresses i.e. .com, .org, .edu, .net, etc. The Internet also took its first steps toward becoming a collaborative private/public/academic effort when private companies for the first time received registrations for backbone network services. In 1995, the number of registrants had grown to 120,000 and the first registration fee was charged. At that point, 97% of the applications for new Internet domain registrations came from commercial applicants.
Early instances of multiple clients sharing a single, sometimes more powerful, computing device were known as local area networks. In these settings, a single central server or computing device supported several stand-alone personal computers or dumb terminals (keyboards and computer screens) housed in the same physical location. Further software and hardware advancements expanded the capabilities of desktop personal computers, and later allowed users to remotely share their work using telecommunication technologies. This model evolved into what are known as distributed networks, which established reliable communication links between personal computers and computing devices over distances.
The mediums used to transmit computer data now include twisted pair, coaxial cables, broadband coaxial cable, fiber optics, and wireless communication devices. The Internet is now accessible from anywhere in the world where computers can gain access to telecommunication services.
As of September 2008, 69 percent of Americans were using webmail services, storing data online, or otherwise using software programs, such as word processing applications, whose functionality is located on the web.
An overwhelming majority of Cloud Computing Services users expressed serious concern regarding the possibility that a Cloud Computing Services provider would disclose their data to others. According to a report of the Pew Internet and American Life Project:
- 90% of cloud application users say they would be very concerned if the company at which their data were stored sold it to another party.
- 80% say they would be very concerned if companies used their photos or other data in marketing campaigns.
- 68% of users say they would be very concerned if companies who provided these services analyzed their information and then displayed ads to them based on their actions.
Future of Personal Computing and Cloud Computing
The advance of cloud computing may allow personal computing devices to become dumber, while remote computing services become much smarter. The ability to exercise consumer rights and privacy rights in a global Internet environment is a serious challenge that regulators and legislatures must tackle.
News Items
- F.T.C.: Has Internet Gone Beyond Privacy Policies? by STEPHANIE CLIFFORD, New York Times, January 11, 2010
- FTC Examining Cloud Computing Privacy Concerns, Daniel's Web Trends Blog, Daniel Nations, About.com Guide to Web Trends, Tuesday January 5, 2010
- Privacy Group Asks FTC to Investigate Google, Preston Gralia, PCWorld, December 19, 2010
- L.A. Cloud Contract Goes To Google Over Microsoft, Patricia Resende New Work Security News, October 29, 2009
- Google Helps Users Jump Ship to Rival Web Services, by Paul Meller, IDG News Service, September 11, 2009
- Lost in the Cloud, Jonathan Zittrain, New York Times, July 20, 2009
- World Privacy Forum Sends Letter to LA Mayor Regarding Cloud Computing Contract, July 17, 2009
- CSC Launches Cloud Services, Justin Lee, Web Host Industry Review, June 12, 2009
- HP Unveils Scale-Out Computing Hardware For Data Centers, Antone Gonsalves, Information Week, June 10, 2009
- Tech Firms Seek to Get Agencies on Board With Cloud Computing, Kim Hart, Washington Post, March 31, 2009
- More Security Loopholes Found In Google Docs, Robin Wauters, Washington Post,TechCrunch.com, March 26, 2009
- Privacy groups to FTC: Investigate Gmail, Picasa, Jaccqui Cheng, Arstechnica, 3/18/2009
- Privacy Group Asks F.T.C. to Investigate Google, Miguel Helft, New York Times, 3/17/2009
- FTC urged to investigate security of Google services, Jeremy Kirk, Network World, 3/18/2009
- FTC questions cloud-computing security, Sephanie Condon, CNET News, 3/17/2009
- Group asks U.S. FTC to probe Google privacy safety, Alexei Oreskovic, 3/18/2009
- FTC To Probe Google Privacy Protections' Adequacy, 3/17/2009
- New Privacy Complaint Filed Against Google (And The Cloud), Greg Sterling, 3/18/2009
- Piracy Police Want FTC To Investigate Google Cloud Services, Maureen O'Gara, Sys-Con Media
- EPIC Petitions FTC to Probe Google, Cloud Computing Services - Update, RTT News, 3/17/2009
- News Group asks FTC to examine Google's reliability, John Letzing, Market Watch WSJ, 3/17/2009
- Who Ya Gonna Call? Cloudbusters!, Alan Williamson, AJAX World Magazine, 3/17/2009
- The Perils Of Cloud Computing: Privacy Group Wants To Take Your Gmail Away, Leena Rao, Tech Crunch, 3/17/2009
- Cloud computing: How we got here, Charles Cooper, CNET.com, 3/16/09 Cloud Computing Begins to Gain Traction on Wall Street, Penny Crosman, 1/6/2009
- Cloud computing is a trap, warns GNU founder Richard Stallman, Guradian (UK),September 2008
- 'Cloud computing' heightens privacy risks, Glenn Chapman, Australian IT, 08/11/2008
- Gartner Says Cloud Computing Will Be As Influential As E-business, Special Report, Garner Newsroom, 6/26/2008
- Five cloud computing questions, Network World, 8/5/2008
- Keep an eye on cloud computing, Amy Schurr, Network World, 7/8/08
- What is cloud computing?, Galen Gruman, Information Age, 6/16/2008
- Privacy commissioner probes cloud computing, Shane Schick - ComputerWorld Canada, 5/29/2008
- What cloud computing really means, Galen Gruman, Eric Knorr, Info World, 4/7/2008
- Cloud Computing's Stormy Side, Andy Greenberg, Forbes, 02/19/2008
- I.B.M. to Push 'Cloud Computing,' Using Data From Afar, Steve Lohr, New York Times, 11/15/2007
- Google and I.B.M. Join in 'Cloud Computing' Research, Steve Lohr, New York Times, 10/08/2007
- Amazon Cloud Computing goes beta, CBR, 8/25/2006
News (Spanish)
- Piden en EEUU una investigación sobre la seguridad de Google, El Mundo | España | AFP, 20-03-09
- Google pode ser investigado sobre segurança de dados de usuários, ComputerWorld | Brazil | Por IDG News Service 19-03-09
- A CAUSA DE UNA FALLA EN SU SOFTWARE DE OFICINA ONLINE | Argentina, 19-03-09
- Piden que se investigue la seguridad de los servicios de Google, Redacción LAVOZ.com | Argentina, 18-03-09
- Reclaman investigar la seguridad de las aplicaciones de Google, Argentina, 19-03-09
- EPIC: "Google servisleri ki?isel bilgiler için tehlike arzediyor, SaintLazarus, Hardware Mania, 19-03-09
- Organización pide que se analice la seguridad de servicios online de Google, El Mercurio | Chile, 18-03-09
- Piden que se investigue la seguridad de los servicios de Google, ABC.es (MADRID), 18-03-09
- Grupos defensores de la privacidad piden la suspensión de los servicios de Google, ELPAÍS.com - Madrid, 18-03-09
- Defensores de la privacidad piden que Google desactive sus servicios hasta que mejore seguridad, Eltiempo.com | Colombia
Resources
- EPIC, FTC Complaint Google Cloud Computing Services, March 17, 2009
- Privacy in the Clouds: Risks to Privacy and Confidentiality from Cloud Computing, World Privacy Forum, February, 23, 2009
- An A to Z of Cloud Computing in New York City
- Cloud Computing Workshop, Center for Information Technology Policy, January 14-15, 2008
- Cloud Computing, Wikipedia
- What is Cloud Computing?
- Envisioning the Cloud: The Next Computing Paradigm, Marketplace Report, March 2009
- TCP/IP, Network Administration, Second Edition, Craig Hunt, O'Reilly & Associates, January 1998
- A Brief History of NSF and the Internet
- Architectural manifesto: An introduction to the possibilities (and risks) of cloud computing

