Saturday, August 26, 2017

Russia mulls limitations on internet exchange points over fears of US eavesdropping

The Russian government plans to take steps to minimize the flow of internet traffic through foreign-based exchange points in order to prevent sensitive data from falling into the hands of US intelligence agencies, Vedomosti newspaper reports.

Vedomosti quoted unnamed sources in the Russian government and presidential administration as saying there are plans to prevent internet service providers and communications companies from channeling web traffic from Russia through foreign-based internet exchange points (IXPs).

The main reason according to the sources is the danger that sensitive data could be decoded and studied by US intelligence agencies such as the National Security Administration (NSA), which has several centers for electronic surveillance throughout Europe.

Though US intelligence agencies may state that the objectives of surveillance involve fighting terrorism and other forms of extremism, it is still possible that in the process they also obtain information concerning bank transfers, official correspondences, and other sensitive data from Russian officials, the sources say.

Representatives of major Russian telecom companies said that only about 20 percent of internet traffic in the country was conducted through foreign IXPs, adding that the main reason for this is cost cutting.

The Vedomosti article appeared after the Russian Communications Ministry published a draft law in mid-August that it intends to send to the Lower House after discussion with government experts. If passed, operators would have to direct Russian web traffic through Russian-based IXPs listed in a special state register. The bill would also set a 20-percent limit on foreign shares in companies that own Russian IXPs, as well as requiring IXPs to keep data logs for at least three years.

If passed, the bill would come into force on July 1, 2018.

The draft law is also in line with a broader package of internet laws usually known in the media as the Yarovaya bills, named after its main sponsor, Lower House MP Irina Yarovaya (United Russia). This set of laws, signed by Russian President Vladimir Putin in July 2016, contains provisions requiring communications companies, including internet providers, to retain their clients’ data for three years (one year for messengers and social networks), and also to keep records of phone calls, messages, and transferred files for six months. Communications companies are also required to hand over encryption keys to state security agencies on demand, allowing them to read encrypted data or face large fines.

After the bill was signed into law, MP Yarovaya told reporters that it had been developed to protect the personal data of Russian citizens from foreign interference, including the “global digital domination of the United States.” She also said that the law would allow Russian companies to create their own technology to protect information from foreign access.

The post Russia mulls limitations on internet exchange points over fears of US eavesdropping appeared first on IAPS Security Services, Ltd. Official Blog.



Russia mulls limitations on internet exchange points over fears of US eavesdropping posted first on https://iapssecurityservices.wordpress.com

Tuesday, August 22, 2017

3 tips for networking in the cloud-hosted economy

In a distributed and connected cloud-hosted application economy, networking plays a key role.

Companies looking to host their workloads with cloud service providers (CSPs) must make informed decisions on how to connect to cloud infrastructures. When choosing CSPs, companies sometimes overlook the importance evaluating networking options. It’s not just about having a network connection, it also requires considering speed, flexibility, latency, the number of hops, redundancy, reliability, telecommunications vendor option and additional provisions.

In addition, companies should evaluate where their users are located, how they would connect to the business application and how users would be authenticated using centrally managed direct structures. Some companies prefer that all users and employees first connect to their corporate network, then ride their intranet to connect to cloud hosted applications.
Here are three networking items to consider:

1. Connecting your corporate network to a cloud vendor.

The two prevalent networking options for connecting to cloud are virtual private networks (VPN) and dedicated lines with defined bandwith.

A VPN is an encrypted tunnel over the internet for data exchange. It’s simple to set up and is used 85 to 90 percent of the time by customers. However, this connection is limited by the provider’s internet bandwidth and is shared traffic over the internet.

For example, a retailer may require each of its geo-dispersed store to constantly connect to an application for access to its hosted enterprise application hosted at the CSP. A VPN may be best suited here.

A dedicated line with defined bandwidth can be provided by large telecommunications vendors that set up their routers in CSP data centers or in their point of presence (POP). It enables a separate, encrypted channel through which customer traffic can reach the CSP.

Internally, telecommunications locations are connected through high-speed fiber lines, which are shared among clients. Dedicated lines can provide much better redundancy and reduced latency than a public network. However, ordering and setting these lines takes a considerable amount of time. Customers should make use of their existing telecommunications providers and connect to their CSPs’ primary and disaster recovery sites.

Large applications such as SAP and Oracle, with many geographically diverse users, require a dedicated line to host their core business application in many cases. Some hosting vendors provide customers the option to connect to one of the POP and internally ride their high-speed fiber to connect all their data centers.
Read More: https://www.ibm.com/blogs/cloud-computing/2017/01/networking-cloud-hosted-economy
Related Article: INSTALL CISCO VPN CLIENT ON WINDOWS 10 (32 & 64 BIT). FIX REASON 442