Cloudflare slams AWS egress fees to convince web giant to join its discount data club
- Reference: 1627085227
- News link: https://www.theregister.co.uk/2021/07/24/cloudflare_aws_egress_fees/
- Source link:
"AWS’s bandwidth pricing is bonkers," said CEO Matthew Prince, [1]via Twitter . "And they stand alone in the industry not discounting when their customers send traffic to peered networks."
Prince and Nitin Rao, SVP of global infrastructure at Cloudflare, elaborated on that claim in a [2]blog post that argues AWS is charging customers orders of magnitude more than its costs and makes a mockery of its parent company's mission statement that Amazon strives "to offer our customers the lowest possible prices…"
[3]You're not imagining it. Amazon and AWS want to hire all your friends, enemies, and everyone in between
[4]JavaScript, GitHub, AWS crowned winners in massive survey of 32,000 developers
[5]AWS gave Parler a chance, won't say if it talked to NSO before axing spyware biz's backend systems
[6]UK's biggest trade union takes aim at Amazon over 'price gouging' allegations
In particular, Prince and Rao take issue with cloud giant's egress data transfer, or bandwidth, pricing – what it charges to send data to external networks.
"During the last ten years, industry wholesale transit prices have fallen an average of 23 per cent annually," explain Prince and Rao. "Compounded over that time, wholesale bandwidth is 93 per cent less expensive than 10 years ago. However, AWS’s egress fees over that same period have fallen by only 25 per cent."
[7]
They further note that since 2018, the egress fees AWS charges in North America and Europe have remained unchanged while wholesale prices in those markets have gone down by more than half.
[8]
[9]
AWS is able to charge excessive rates, they suggest, because customers pay for delivered data volume while AWS pays for bandwidth based on the capacity of its pipes. This difference – charging customers using a "stocks" model while incurring costs under a "flow" model – leaves lots of room for AWS to profit based on effective utilization of its resources.
The pair made various estimates for AWS's data transfer profit margin, using the [10]AWS Simple Monthly Calculator – ironically named, they contend, in reference to AWS's famously [11]difficult-to-understand pricing scheme . They project, for example, that AWS charges customers in the US, Canada, and Europe 80 times more than its operational cost.
[12]
What's more, they argue, the effective markup is likely to be higher still because when AWS exchanges data with a network like Cloudflare using a direct, settlement-free peered connection though a private network interface, incremental costs are negligible. And there are also rebates that Amazon collects from colocation providers who charge cross connection fees to customers to consider.
Welcome to the Hotel California
Only AWS, however, is in a position to provide data on its actual costs but the company has not done so – most businesses keep such details to themselves.
Prince and Rao also suggest there's an anti-competitive aspect of AWS's decision to charge a premium for data leaving its ecosystem (egress) but not for data entering its ecosystem (ingress).
They liken this to "Hotel California pricing," a reference to a line from The Eagle's 1976 song of the same name that describes a place where you can never leave. The implication is this pricing model deters companies dependent on AWS from choosing to move their data and business elsewhere, even though Google and Microsoft also charge for data egress.
"The only rationale we can reasonably come up with for AWS’s egress pricing: locking customers into their cloud, and making it prohibitively expensive to get customer data back out," they said. "So much for being customer-first."
[13]
Some AWS users have come to this conclusion too.
324TB/month can 100% be cheaper outside of AWS. Within AWS it’s closer to $30k than $20k.
AWS egress (and all cloud providers) is absurdly expensive and AWS should publish the margins they make on those links.
It’s also a hidden cost and dark pattern pricing. [14]pic.twitter.com/ghXf2ykPAx — Randall Hunt (@jrhunt) [15]June 2, 2021
However, the [16]pricing for data egress from [17]Google Cloud Platform (~$0.11) and [18]Microsoft Azure (~$0.0875 per GB) for 10 TB doesn't appear to be vastly different from [19]AWS (~$0.09 per GB), at least on paper.
What makes Cloudflare single out AWS is that Microsoft Azure and Google Cloud, while neither participate in the [20]Bandwidth Alliance , "will substantially discount egress charges for their mutual Cloudflare customers."
In short, Cloudflare is sticking it to AWS in the hope the cloud service giant will play ball and play nice.
The Bandwidth Alliance, Cloudflare said in [21]a separate post , can save customers between 7.5 per cent and 27 per cent on egress data transfer charges. Presently the group consists of: Alibaba, Automattic, Backblaze, Cherry Servers, Dataspace, DNS Networks, DreamHost, HEFICED, Kingsoft Cloud, Liquid Web, Scaleway, Tencent, Vapor, Vultr, Wasabi, and Zenlayer.
The Register asked Amazon for a response. The web titan expressed its intention to so do though its reply did not arrive by our deadline. We will update this story once we hear back.
If we had to guess, we'd predict that Cloudflare's negotiation via social media won't make AWS abandon its cloud-based printing press for cash. And while the Attorney General of Washington DC recently filed [22]an antitrust lawsuit against Amazon over alleged retail market abuses, its AWS subsidiary remains for the moment unthreatened by regulatory intervention. ®
Full disclosure: The Register is a customer of Cloudflare.
Get our [23]Tech Resources
[1] https://twitter.com/eastdakota/status/1418572488733122564?s=20
[2] https://blog.cloudflare.com/aws-egregious-egress/
[3] https://www.theregister.com/2021/07/21/amazon_aws_recruitment/
[4] https://www.theregister.com/2021/07/16/jetbrains_developer_survey_2021/
[5] https://www.theregister.com/2021/07/21/aws_parler_response_vs_nso_response/
[6] https://www.theregister.com/2021/07/14/uks_largest_trade_union_takes/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/paasiaas&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YPvkw69Qth@KCNlvtA9rHwAAAMY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/paasiaas&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YPvkw69Qth@KCNlvtA9rHwAAAMY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/paasiaas&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YPvkw69Qth@KCNlvtA9rHwAAAMY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://calculator.s3.amazonaws.com/index.html#key=files/calc-917de608a77af5087bde42a1caaa61ea1c0123e8&v=ver20210710c7
[11] https://www.duckbillgroup.com/blog/understanding-data-transfer-in-aws/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/paasiaas&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YPvkw69Qth@KCNlvtA9rHwAAAMY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/paasiaas&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YPvkw69Qth@KCNlvtA9rHwAAAMY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://t.co/ghXf2ykPAx
[15] https://twitter.com/jrhunt/status/1400009323787427841?ref_src=twsrc%5Etfw
[16] https://www.hostdime.com/blog/data-egress-fees-cloud/
[17] https://cloud.google.com/vpc/network-pricing
[18] https://azure.microsoft.com/en-us/pricing/details/bandwidth/
[19] https://aws.amazon.com/ec2/pricing/on-demand/
[20] https://www.theregister.com/2018/09/26/cloudflare_bandwidth_gouging/
[21] https://blog.cloudflare.com/empowering-customers-with-the-bandwidth-alliance/
[22] https://oag.dc.gov/release/ag-racine-files-antitrust-lawsuit-against-amazon
[23] https://whitepapers.theregister.com/
Re: Man in the middle attack
It sounds like you should be writing an extension for Firefox. That behavior regarding certificates is more complex than a browser typically supports--you can easily remove or distrust a certificate, but providing the data on each load isn't going to get added. It should be easy enough to implement by someone willing to write the code though.
Bears/woods
Shocking news just in, "Cloud providers, who make money for per/GB storage, charge almost nothing to take in data but charge shed loads to let you take your data out!".
My "bleedin' obvious" alarm is off the chart! Seriously, why you moaning now? All the providers have done this for years. I remember signing up for Glacier back around 2012 and that was stated clear as daylight in Amazon's docs, "Put your data in for almost nothing, storage will cost almost nothing, taking it out is where we will charge you and here is how much per GB.".
Re: Bears/woods
They're pretending it's news to shame AWS into having a special arrangement with them.
Man in the middle attack
A content deliver network, substituting a fake cert, issued by itself or partner companies, in place of the actual real certificate, is a man-in-the-middle attack.
It was found to be a problem, Google has caught lots of countries faking its own certs, India, Egypt, even USA: Symantec was caught issuing fake Google certs:
https://www.pcmag.com/news/google-slams-symantec-over-fake-certificates
Is it a big problem? Do bears shit in the woods? Yes its a big problem! You cannot secure your banking, web instrumentation, IoT devices or anything else if any certificate authority can fake any website certificate.
Add a Content Delivery Network (CDN) to the mix, and these fake certs can be issued PER USER and PER DEVICE, since the content deliver network controls the delivery of the website targetted at that user. On a PER USER basis the CDN can swap in the fake cert. The chance of INDIVIDUAL USER detecting those certs as fake is nill. These per user fake certs go undetected.
Avoid CDNs, you're exposing your customer data.
It's not enough to avoid CDNs, routes can be force by returning false data to skew routing algorithms, they can be force by returning false DNS queries, I've seen examples of this myself recently. You need to USE CERTIFICATE PINNING too.
If you don't believe me, here's Digicert FUDding Certificate Pinning:
https://www.digicert.com/blog/certificate-pinning-what-is-certificate-pinning
Look at an example, how piss poor their claims are:
"Sometimes CAs must revoke your certificates. Maybe an audit shows the certificates have previously unknown issues, like misspellings in the subject name or invalid entries in the OU fields. Industry standards say the CA has five days to revoke your certificates, but you pinned them in your client code. How can you push out updates to all your clients in five days to start using your new replacement certificates?"
Why would a GOOD certificate authority try to stop you using a certificate verification mechanism designed to stop a ROGUE certificate authority issuing fake certs? A man-in-middle attack that has been done many times by ROGUE certificate authorities. My personal suspicion is that they are ROGUE, and that widespread use of pinning would throw up lots of "hold up, this site isn't supposed to have a DIGICERT certificate, something is rogue here".
Improvements need to be made to CERT PINNING too.
I want to be able to set all certficate authorities as untrusted, trusted, or "ask me per website", with a "always reject for this site" or "always accept for this site", for the latter.
I want a mechanism in Firefox to report certs I am suspicious of, for investigation, and to automatically report pinned violations.
You backdoored the internet and you undermined your security, and now you're bitching because your security is undermined.