Google Cloud Platform is now FedRAMP High authorized

At Google Cloud, we’re committed to providing public sector agencies with technology to help improve citizen services, increase operational effectiveness, and better meet their missions. We  build our products with security and data protection as core design principles, and we regularly validate these products against the most rigorous regulatory requirements and standards.  To that end, we are proud to announce that Google Cloud Platform (GCP) has received FedRAMP High authorization to operate (ATO) for 17 products in five cloud regions, and we’ve expanded our existing FedRAMP Moderate authorization to 64 products in 17 cloud regions. This means that public sector agencies now have the ability to run compliant workloads at the highest level of civilian classification.How FedRAMP certification worksFedRAMP is a U.S. government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services offered to US federal government agencies. Most federal agency cloud deployments and service models, other than certain on-premises private clouds, must meet FedRAMP requirements at the appropriate (Low, Moderate, or High) risk impact level. While Google Cloud already maintains an authorization for both GCP and G Suite at the Moderate impact level, achieving High status on GCP means we can provide greater access to technology for our most security-sensitive customers. And while the FedRAMP ATO is required for federal agencies, it is also a security benchmark for other industries, including financial services, health, and manufacturing. If you’re a GCP customer, you can enjoy the benefit of a FedRAMP High-authorized infrastructure at no additional cost and without any change in your services. Obtaining FedRAMP High required documenting at length how our infrastructure and platforms help our customers keep their data safe. We carefully translated the principles of our BeyondCorp model, including zero-trust networking, that we have implemented at Google into the NIST 800-53r4 security controls, which were then documented and assessed by a third-party organization. As part of this process, we also completed FIPS 140-2 L1 overall and L3 physical FIPS validation of the internal version of Google’s Titan Security Key authenticator. We worked closely with the FedRAMP Joint Authorization Board to document Google’s monitoring, patching, and vulnerability scanning infrastructure in order to meet the rigorous continuous monitoring requirements of FedRAMP High. Receiving a FedRAMP High ATO means we can support agency missions that require some of the highest levels of data protection for unclassified workloads. These could include health care delivery, emergency response, space operations, and many others. Supporting the public sector with cloud innovationThese new certifications reflect our continued investment and support for customers in the U.S. public sector, and is another example of momentum we’re seeing as government agencies move to the cloud. For example, we recently teamed up with researchers from NASA-FDL to help identify life beyond earth with our machine-learning capabilities, and the Library of Congress team spoke at Google Cloud Next ‘19 on how they’re making books accessible to the visually impaired. We are also helping the U.S. Air Force modernize its modeling and simulation training infrastructure.  At the state and local level, the State of Arizona plans to migrate thousands of employees and contractors to G Suite to improve security and collaboration. It anticipates millions of dollars in cost savings over the next three years. And New York City Cyber Command is partnering with Google Cloud to automate and speed log analysis and other initiatives to protect New Yorkers from malicious cyber activity, while also safeguarding data privacy on mobile devices and across public WiFi networks. Welcoming new public sector leadersToday’s news reinforces our commitment to the public sector. Earlier this year, I joined Google Cloud to lead our public sector efforts. We’ve also added Brent Mitchell to lead Google Cloud’s state and local government strategy, and Lesta Brady to head up our federal civilian sales strategy. And we recently announced a new Global Public Sector organization within Google Cloud, with a charter of engaging with public sector customers worldwide—and have welcomed new leaders in Canada, EMEA, and Latin America into this organization. Finally, I’m excited today to announce that long-time Googler and Chief Internet Evangelist Vint Cerf and his group of technology specialists will be joining my team to bring their expertise to public sector customers globally. His team will continue to evangelize the potential of the internet and the solutions it can enable, which is critically important for public sector decision-makers to understand as part of the delivery of their services. We look forward to continuing to help federal, state, and local government agencies innovate, and will pursue additional global certifications to meet their needs. You can learn more here about our public sector work.
Quelle: Google Cloud Platform

RSA-240: Faktorisierungserfolg gefährdet RSA nicht

Forscher haben auf einem Rechencluster eine 795 Bit große Zahl faktorisiert. Das RSA-Verschlüsselungs- und Signaturverfahren basiert darauf, dass Faktorisierung schwierig ist. Für die praktische Sicherheit von RSA mit modernen Schlüssellängen hat dieser Durchbruch heute aber wenig Bedeutung. (Wissenschaft, Technologie)
Quelle: Golem

Wavefront Automates and Unifies Red Hat OpenShift Observability, Full Stack

This is a guest post by Gordana Neskovic (@nesgor), a Senior Product Marketing Manager for Wavefront by VMware. Gordana has held Data Scientist / AI Architect roles at Wells Fargo, Pinterest, and SFO-ITT. Her current interests are at the intersection of cloud monitoring, operational analytics, and data science. She holds a Ph.D. in Electrical Engineering.
Special Thank You to Anirban Dey (@Anirbandey2011), and Srinivas Kandula (@kanduls) for contribution to this blog.
Anirban is a Product Line Manager at Wavefront by VMware. He is currently involved with expanding the Wavefront Integration portfolio and building new Wavefront integrations. He loves to learn and play with all the latest technologies around the developer platform/ecosystem and solve critical customer problems. In his spare time, he loves to travel, explore various cuisines, and listen to music.
Srinivas is a Staff Engineer at Wavefront By VMware. He is currently working on adding more integrations to Wavefront. He loves to learn and play with the latest technologies and build solutions with them. In his spare time, he loves to go cycling, swimming, and running.
Red Hat OpenShift is an enterprise Kubernetes platform intended to make the process of developing, deploying and managing cloud-native applications easier, scalable and more flexible. Wavefront by VMware provides enterprise-grade observability and analytics for OpenShift environments across multiple clouds. Wavefront ingests, analyzes and visualizes OpenShift telemetry – metrics, histograms, traces, and span logs – across the full-stack, including distributed applications, containers, microservices, and cloud infrastructure. 
 As a result of Wavefront’s collaboration with Red Hat, you can now get automated enterprise observability for OpenShift that’s full stack, through the Red Hat OpenShift Certified Wavefront Operator for OpenShift 4.1 and later. This Operator is available in Operator Hub embedded in OpenShift, a registry for finding Kubernetes Operator-backed services. 
 With the Red Hat OpenShift Certified Wavefront Operator, engineers, developers, and OpenShift operators get:

Accelerated and automated transition into Kubernetes and applications observability 
Streamline day 2 observability operations – from deployments of the Wavefront Collector for Kubernetes and Wavefront proxies to managed configurations and upgrades
Automated full-stack enterprise observability and deep insight analytics across OpenShift environments

Figure 1: Complete Visibility into OpenShift Cluster Nodes, Namespaces, Pods, Containers
What’s the Red Hat OpenShift Certified Wavefront Operator?
The Red Hat OpenShift Certified Wavefront Operator installs, upgrades and constantly checks the health of the Wavefront Collector for Kubernetes. It reduces costs and risks of managing observability for OpenShift environments and applications at scale. It also improves time-to-value by pretesting and expediting the Wavefront Collector for Kubernetes deployment and configuration.
In essence, the Red Hat OpenShift Certified Wavefront Operator is a method of packaging, deploying, and managing OpenShift observability using the Kubernetes APIs and kubectl tooling. The Operator runs in a pod on the cluster and interacts with the Kubernetes API server. It installs a Wavefront Collector for Kubernetes instance on each node in the OpenShift cluster, taking advantage of resource definitions, an extension mechanism in Kubernetes. Unless you specify you want to send data to Wavefront using direct ingestion, the Operator also installs and configures one or more Wavefront proxies. The Operator watches for Wavefront Collectors for Kubernetes instances and is notified when they are being added or modified. When the Operator receives a notification, it starts running a loop to ensure that all the required connections between the Wavefront Collector for Kubernetes and the OpenShift environment are available and are configured in the way the user expressed in the specification.
 The Red Hat OpenShift Certified Wavefront Operator also provides for the new Wavefront Collector for Kubernetes versions to be deployed using a rolling update, avoiding downtime and making it easy to stay up-to-date.
Through continuous certification, the interoperability and safety of the Red Hat OpenShift Certified Wavefront Operator is verified on an ongoing basis, with a fast turnaround for security updates. 
Installing Red Hat OpenShift Certified Wavefront Operator
It’s easy to install the Red Hat OpenShift Certified Wavefront Operatorby following these steps:

Using the OpenShift administrator console web interface, browse to the OpenShift OperatorHub
Search for Wavefront Operator
Click on the Wavefront Operator tile
Go through Wavefront Operator Overview and check all the operator metadata and links
Click on the Install button
Follow the step-by-step installation instructions

Enterprise Observability for OpenShift that’s Automated and Full-Stack
Once the Red Hat OpenShift Certified Wavefront Operator is installed and configured, Wavefront:

Automatically recognizes Kubernetes services
Discovers Kubernetes workloads and instruments Java-based services across any cloud
Populates pre-packaged multi-layered Kubernetes dashboards
Reports at scale, up to 1-sec resolution (sub-1-sec with histograms), streaming health and SLO metrics for OpenShift clusters, nodes, pods, and containerized applications
Provides detailed information about Kubernetes environment operations and autoconfigure a set of Kubernetes-related alerts 

Figure 2: Wavefront Enterprise Observability for OpenShift, Full-Stack
You can now start using and customizing the out-of-the-box pre-configured dashboards. You can alleviate code issues by understanding Kubernetes system metrics and instantly troubleshoot containers and applications microservices. With Wavefront’s powerful analytics, you can correlate and quickly drill down across applications running on OpenShift, containers, Kubernetes, and cloud. 
Also, engineers such as developers and SREs can deep-dive into any incident using distributed tracing to trace transactions across distributed services and identify root cause in seconds. With Wavefront’s sophisticated AI-driven performance analytics and trends prediction, you can proactively get an alert on anomalies across containerized applications running on OpenShift environments. 
Ready to Get Started?
If you’d like immediate, deep visibility into your entire OpenShift environment, sign-up for a Wavefront free trial. With the Red Hat OpenShift Certified Wavefront Operator , you will benefit from accelerated transition into enterprise observability for OpenShift that’s automated and full stack. Wavefront streamlines day 2 observability operations, providing deep insight analytics across your entire OpenShift environment, including containerized applications, Kubernetes, and the underlying infrastructure. 
 
The post Wavefront Automates and Unifies Red Hat OpenShift Observability, Full Stack appeared first on Red Hat OpenShift Blog.
Quelle: OpenShift