back to article No root for you, or how to stop worrying and love AWS China

If you open an AWS account in China, you don't get a root account; instead, one of Amazon's Chinese operating partners, Sinnet or NWCD, has root access and creates an IAM admin user for you. Nikki Bailey, senior devops engineer at Illumina, a company that builds gear to sequence genetic data, explained as much at the DevOps- …

  1. Mayday
    Thumb Down

    So let me understand this?

    You don't get a root account, but someone else "manages" root for you?

    Can't say I'm too surprised of course.

    1. whitepines
      Trollface

      Re: So let me understand this?

      How is that different than AWS anywhere else, where Intel and AWS have the real root account(s)? Your "root" account is just a second tier login to manage your little corner of their machine under the watchful eye of your guardians...

  2. Anonymous Coward
    Anonymous Coward

    Goddamn, F China

    Talk about a deal with the devil...

    1. Anonymous Coward
      Anonymous Coward

      Re: Goddamn, F China

      If anyone, the devil is you. If my memory serves me right, the literal translation of "foreigner" from Chinese is "foreign devil".

      1. jake Silver badge

        Re: Goddamn, F China

        But AC2, for all you know AC1 is Chinese ...

  3. jake Silver badge

    WOW!

    Just exactly what I've been waiting for!

    ::rolls eyes::

  4. Sitaram Chamarty

    "the internet treats..."

    "The internet treats censorship as damage, and routes around it". Wasn't that what people say?

    I'd say China has found a way to break that. If you have to apply for a permit to serve port 80 or 443, and you don't get root on a machine you have at least rented, the amount of "routing around" you can do is pretty damn limited!

    I think all wannabe totalitarians (and I am not excluding India's Aadhaar-crazed government here, and the USA was anyway only a democracy in name for some time) taking a good look and thinking... hmm, if China can do it, why can't I?

    I wonder if, in about 20 years or so, all of the dystopian fantasies of Richard Stallman and Cory Doctorow would have come true.

    1. jake Silver badge

      Re: "the internet treats..."

      No, China hasn't found a way to break that. TheInternet (whatever that is) has detected the damage, and is routing around China's b0rken intranet.

  5. Michael Hoffmann Silver badge
    Unhappy

    Self-baked AMIs?

    I'm curious as to how they would do that. It's a 5 line user-data script to add a custom account and add that one to sudoers - and user-data is run as root.

    Not that I'd be surprised to hear what they do to prevent that - can't even bake your own AMIs, they filter all user-data, *prohibit* user data (or cfn-init/cloud-init)? I'd love to see their IAM profiles :P

    How that is to ever lead to a culture of innovation (as opposed to copy-catting) is beyond me. But as long as our corporate overlords are happy to have our daily tat produced by cheap and oppressed quasi-slave labour to sell it at max profit here, I suppose the system works.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like