Slashdot Mirror


Ask Slashdot: Secure DropBox Alternative For a Small Business?

First time accepted submitter MrClappy writes "I manage the network for a defense contractor that needs a cloud-based storage service and am having a lot of trouble finding an appropriate solution that meets our requirements. We are currently using DropBox and I am terrified of seeing another data leak like last year. Some of our data is classified under International Traffic in Arms Regulations (ITAR) which requires that all data to remain inside the US, including any cloud storage or redundant backups. We tried using Box as a more secure replacement but ended up canceling the service due to lack of functionality; 40,000 file sync limit, Linux-based domain controller compatibility issues and the fact that the sync application does not work while our computers are locked (which is an explicit policy for my users). I've been calling different companies and just can't seem to find a decent solution. Unless I'm severely missing something, I'm just blown away that no one offers this functionality with today's tech capabilities. Am I wrong?"

11 of 274 comments (clear)

  1. You are kidding right? by MerlynEmrys67 · · Score: 5, Informative

    You want "Someone Else" to manage your data that is classified under ITAR? Uhmmm... Why don't you build your backup solution - put links in to remote data centers and handle the problem correctly and professionally. The last thing we need is some external entity getting a hold of this stuff because you don't want to have the budget to do things right instead of at a consumer level.
    Gah - I can't believe this is even a question

    --
    I have mod points and I am not afraid to use them
    1. Re:You are kidding right? by ravenswood1000 · · Score: 5, Informative

      Try Owncloud or Ajaxplorer for your own cloud solution maybe.

    2. Re:You are kidding right? by pixelpusher220 · · Score: 5, Funny

      I believe there's a facility in Utah that specializes in cloud data storage...

      --
      People in cars cause accidents....accidents in cars cause people :-D
    3. Re:You are kidding right? by sconeu · · Score: 5, Insightful

      I agree with Merlyn. Are you F***ING INSANE?????? Especially after the way that the gov went batshit insane over Wikileaks and then over Snowden.

      I know that "classified under ITAR" is not "Classified secret", but you'd be crazy to trust that data to any storage that you (or your company) doesn't directly control.

      Disclaimer: I am not an ISSO or ISSM (though at one point I did get certified as one -- long since lapsed).

      --
      General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
    4. Re:You are kidding right? by ColdWetDog · · Score: 5, Funny

      I can just see this - a high level presentation to the C level executives:

      "Yes, we're planning on using Sparkleshare".

      "Sparklewhat?"

      "Sparkleshare, it's an open source product that ...."

      "Look, we're here to discuss corporate data strategy, not your daughter's favorite website".

      --
      Faster! Faster! Faster would be better!
  2. I call bull by santax · · Score: 5, Interesting

    "I manage the network for a defense contractor that needs a cloud-based storage service" No you don't. At least I sure as hell hope you don't. Cloud + defense don't mix but since you are managing such a network, why am I telling you this? Why don't you contact 'defense' for options...

    1. Re:I call bull by hawguy · · Score: 5, Insightful

      "I manage the network for a defense contractor that needs a cloud-based storage service"

      No you don't. At least I sure as hell hope you don't. Cloud + defense don't mix but since you are managing such a network, why am I telling you this? Why don't you contact 'defense' for options...

      That was my first thought when I saw his message. It doesn't seem that any commercial Dropbox like service would provide enough fine grained ACL's and reliable and untamperable logging to properly secure any kind of "classified" data. It seems like keeping the data locked up in a VPN accessed fileserver would be better with restrictions on the computer that prohibit saving to local storage. Once it's on a dropbox like service, how do you keep an exec from syncing the entire restricted folder to his laptop before his overseas trip to China, thus violating the rules about keeping it on US soil?

    2. Re:I call bull by Wintermute__ · · Score: 5, Informative

      Sadly, I think this guy might be for real. Notice he didn't say "classified", merely "ITAR-restricted". Those are nowhere close to the same thing. Yet, if you get caught messing up with ITAR data, it's still up to a million-dollar fine per instance I believe. Reason enough to tell your lusers "No, you may not use Dropbox" and block it at the firewall.

      Defense contractor - I'm thinking sub-contractor or sub-sub-contractor. There are so many small companies with no budget and less clue handling this kind of dangerous but not classified data out there, it's scary.

  3. AWS? by Anonymous Coward · · Score: 5, Interesting

    I know that Amazon Web Services have several cloud-based sites that are certified to not allow traffic out of the US (I work there currently). I don't know how it fits your other needs, but there are a number of government agencies that use them.

  4. Never going to find one by Archfeld · · Score: 5, Informative

    I've worked contingency operations and recovery for data under federal regulations. You will NEVER find a service that will provide the kind of security, financial and geographical restrictions that you really need. That is the single most compelling reason why banks have backup data centers...

    --
    errr....umm...*whooosh* *whoosh* Is this thing on ?
  5. AWS GovCloud by Anonymous Coward · · Score: 5, Informative

    I know that Amazon Web Services have several cloud-based sites that are certified to not allow traffic out of the US (I work there currently). I don't know how it fits your other needs, but there are a number of government agencies that use them.

    Look here -> https://aws.amazon.com/govcloud-us/