<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ben Cherian's blog &#187; hype</title>
	<atom:link href="http://bencherian.com/tag/hype/feed/" rel="self" type="application/rss+xml" />
	<link>http://bencherian.com</link>
	<description>putting cloud computing to the test</description>
	<lastBuildDate>Mon, 16 Mar 2009 11:31:14 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Mosso&#8217;s disingenuous PCI-compliance claim</title>
		<link>http://bencherian.com/2009/03/mossos-disingenuous-pci-compliance-claim/</link>
		<comments>http://bencherian.com/2009/03/mossos-disingenuous-pci-compliance-claim/#comments</comments>
		<pubDate>Sun, 15 Mar 2009 15:56:36 +0000</pubDate>
		<dc:creator>ben</dc:creator>
				<category><![CDATA[mosso]]></category>
		<category><![CDATA[hype]]></category>
		<category><![CDATA[pci]]></category>

		<guid isPermaLink="false">http://bencherian.com/2009/03/mossos-ingenuous-pci-compliance-claim/</guid>
		<description><![CDATA[I&#8217;m a big fan of RackSpace and their Mosso product. The Mosso team has done a great job by continually tweaking their products to add more functionality and value. They have made intelligent purchases (JungleDisk/SliceHost) and are using their considerable resources to make a lasting impact on the cloud computing landscape. I&#8217;ve had the pleasure [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m a big fan of RackSpace and their <a href="http://www.mosso.com/" target="_blank">Mosso</a> product. The Mosso team has done a great job by continually tweaking their products to add more functionality and value. They have made intelligent purchases (JungleDisk/SliceHost) and are using their considerable resources to make a lasting impact on the cloud computing landscape. I&#8217;ve had the pleasure of working with some of their smart, passionate employees (Rackers) and can personally vouch for their fanatical service. My company, ServiceCloud, has been a RackSpace partner for a couple of years and, when the fit makes sense, we proudly recommend RackSpace/Mosso to our clients.</p>
<p>That being said, I&#8217;m disappointed in Mosso for putting out a more-hype-than-substance announcement. Mosso recently <a href="http://blog.mosso.com/2009/03/cloud-hosting-is-secure-for-take-off-mosso-enables-the-spreadsheet-store-an-online-merchant-to-become-pci-compliant/" target="_blank">announced</a> that they&#8217;ve <strong><em>enabled</em></strong> one of their clients to be PCI-compliant on the Mosso cloud. When I saw this, I wondered how it was possible, but as I read closer it became clear that <strong>it was just a trick!</strong> It seems that their <strong>&#8220;PCI-compliant&#8221;</strong> solution <strong>requires Mosso not to store any information that requires PCI compliance</strong>. Instead they offload the burden of compliance to a third-party payment gateway (Authorize.Net). <a href="http://rationalsecurity.typepad.com/blog/2009/03/how-to-be-pci-compliant-in-the-cloud.html" target="_blank">Chris Hoff</a> and <a href="http://cloudsecurity.org/2009/03/14/what-does-pci-compliance-in-the-cloud-really-mean/">Craig Balding</a> have written excellent articles explaining this trickery.</p>
<p>While what they say in the announcement is <em>technically</em> true, it&#8217;s misleading at best and does the fine team at Mosso/RackSpace a disservice. <strong>There is enough hype in cloud computing.</strong> We expect more from a market leader like Mosso. They clearly don&#8217;t need to stretch the truth in order to make news&#8230;they should just <a href="http://blog.mosso.com/2009/03/cloud-files-emerges/" target="_blank">talk </a><a href="http://blog.mosso.com/2009/03/breaking-news-mosso-the-rackspace-cloud-announces-availability-of-cloud-servers-and-more/">about</a> <a href="http://blog.mosso.com/2009/03/mosso-gets-musical-with-noisetrade/" target="_blank">their</a> <a href="http://blog.mosso.com/2009/02/welcome-to-the-jungle-the-rackspace-cloud-welcomes-jungle-disk-to-the-family/" target="_blank">real</a> <a href="http://blog.mosso.com/2009/02/everythings-bigger-in-texas-slicehost-vps-hosting/" target="_blank">accomplishments</a>.</p>
<p><strong>Update:</strong> The General Manager of Mosso, Emil Sayegh, pinged me on Twitter and mentioned that Greg Hrncir, Mosso&#8217;s Director of Operations, responded to the criticisms on <a href="http://cloudsecurity.org/2009/03/14/what-does-pci-compliance-in-the-cloud-really-mean/#comment-240" target="_blank">Craig&#8217;s site</a>. There also seems to be a healthy back-and-forth at <a href="http://rationalsecurity.typepad.com/blog/2009/03/how-to-be-pci-compliant-in-the-cloud.html#comment-6a00d83451be3669e2011168f7e228970c" target="_blank">Hoff&#8217;s site</a>. It&#8217;s great to see that Mosso is interested in having a dialog about this issue and I&#8217;m looking forward to see how this unfolds.</p>
]]></content:encoded>
			<wfw:commentRss>http://bencherian.com/2009/03/mossos-disingenuous-pci-compliance-claim/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>
