Premium Brand Villeroy & Boch Trusts in Innovation And

Total Page:16

File Type:pdf, Size:1020Kb

Premium Brand Villeroy & Boch Trusts in Innovation And CUSTOMER SUCCESS STORY Growth in 70% performance uplift for More efficient absorption of Optimized user experience e-commerce critical product experience peaks and faster web page thanks to faster web page management applications load times load times and better search engine rankings Global player in e-commerce: premium brand Villeroy & Villeroy & Boch AG has been a global Boch trusts in innovation and leading ceramics producer for over 270 years. Headquartered in Mettlach, close to Germany’s borders with France and cutting-edge IT infrastructure Luxembourg, the company is a byword for well-designed, high-quality products in the Respected global ceramics producer goes digital: keen to ensure bathroom, wellness and tableware. swift, agile responsiveness around the world and constantly www.villeroy-boch.com committed to top quality, Villeroy & Boch AG has opted to further INDUSTRY expand its digital infrastructure. Supported by the European IT Manufacturing/Retail infrastructure provider OVHcloud, the venerable company is using HEADQUARTERS ™ VMware vSAN to migrate to a VMware hybrid-cloud ready data Mettlach, Germany center. The result? Optimized product experience management and improvements to its entire multichannel product communication. In ABOUT OVHcloud OVHcloud is a global leading European tech this way, Villeroy & Boch has, at a stroke, mastered the challenge group that makes dedicated server, software of surging online demand. With a modernized IT infrastructure now and infrastructure modules available to help developers and businesses manage, protect in place, its customers are happier, sales are heading north, and and scale their data. A global player in its own new markets are being tapped. right, OVH builds its own servers, manages 400.000 servers in 30 data centers on four continents and operates its own fiber-optic network. It serves more than 1.5 million Innovative, international and strong on design – since 1748 customers in more than 130 countries. Villeroy & Boch combines a sense of tradition with a spirit of innovation and stands for class www.ovhcloud.com/de/ and sophistication. Since its foundation in 1748, the company has developed into one of the world’s leading brands in the ceramics industry and at the same time into a lifestyle brand. VMWARE FOOTPRINT The renowned premium brand is headquartered in the picturesque Old Abbey in Mettlach VMware Cloud Foundation™ on the Saar River, close to Germany’s borders with France and Luxembourg. Armed with 14 VMware vSAN™ production facilities across Europe, Asia and the Americas, the company – publicly traded since 1990 – today employs 7,500 people in 125 countries. Villeroy & Boch AG’s core 1 Global player in e-commerce: Premium brand Villeroy & Boch trusts in innovation and cutting-edge IT infrastructure Efficient data storage for digital asset management “Our aim is to provide content for our sales channels efficiently and as quickly as possible. But we also want consistent high quality and content that is as standardized as it can be,” says Erik Heinen, Team Lead Enterprise Content Management, Villeroy & Boch. “The big question for us was how best to unify content from creation through the technology to delivery.” Systems need to advance and improve if quality and speed are to be up to scratch. Understanding the benefits of an OPEX-based IT model as opposed to a CAPEX-based one, Villeroy & Boch opted for a cloud-based model at a very early stage. The ceramics producer first approached OVHcloud back in 2014, recruiting it as a competent IT infrastructure provider to drive its digital transformation and migration to the cloud. OVHcloud is committed to supplying its customers with innovative data center technologies. “In 2014, we migrated our entire web landscape to the OVHcloud, which runs on a VMware infrastructure,” says Jens Schneider, Senior Web Engineer at Villeroy & Boch. “Back then, the scope was still manageable: twenty virtual machines – from web servers to database servers to load balancers. Since then we have developed an enormous demand for capacity - we are now at 90 VMs.” “High-quality, first-class content must be business splits into bathroom and wellness and tableware. made available to the various sales Numerous design and innovation awards testify to the continuous development of the premium brand, which today sets channels in a timely and automated new standards in product development and the digitalization of manner. Thanks to a high-performance distribution channels, among other things. infrastructure from OVHcloud and Awareness in tradition in the growing VMware, we are able to manage critical e-commerce space applications more efficiently and deliver Like other companies, Villeroy & Boch is feeling the impact of the general market trend toward e-commerce. It has responded by accurate, complete and consistent setting the goal of refining its digital strategy and capturing more product information.” growth in online business. The relentless increase in online trading worldwide – especially the shift in consumption patterns– ERIK HEINEN creates a need for leading-edge IT solutions. If it is to safeguard TEAM LEAD ENTERPRISE CONTENT MANAGEMENT, its global brand footprint, stay competitive and efficiently master VILLEROY & BOCH the digital transformation, Villeroy & Boch must sharpen its own innovative capabilities, become more flexible and adaptable and cut costs. Since the migration six years ago, the expectations Villeroy & The company must also rise to the challenge of today’s more Boch places on its IT systems – including the hardware – have demanding technical requirements, especially with regard to its risen sharply. To stay ahead of the performance curve, it thus internal product experience management system. The latter became critical to switch to more innovative and more modern combines a product information system (PIM) and a media asset technology. A further milestone was therefore reached when the management system (MAM). Why is all this necessary? As the company migrated to a hybrid-cloud ready data center based on spectrum of providers broadens continually and more and more VMware vSAN in 2020. That underpins our PIM and MAM traffic clogs up websites and e-shops, superior power and systems with the very latest storage technology, giving us performance is a must. At the same time, Villeroy & Boch found significant performance gains thanks to the migration,” Heinen that its hardware too was straining at the limits: modernization notes. “We wanted to migrate with no downtime,” adds Khaled was therefore vital for it to stay on top of growing demands. CUSTOMER SUCCESS STORY | 2 Global player in e-commerce: Premium brand Villeroy & Boch trusts in innovation and cutting-edge IT infrastructure Allab, Sales Director Enterprise at the OVH Group. “So we always keep the entire product range fully up to date and keep invested sufficient up-front time in the proof of concept before it available across all channels,” explains Jens Schneider. For efficiently shifting the entire infrastructure – comprising 100 Villeroy & Boch, automating output to the e-commerce terabytes of data storage – in less than twelve hours.” channels is essential: this is the way in which its own web shop is supplied, alongside the Otto Group or Amazon. Looking back on so many years of very successful partnership with OVHcloud, Villeroy & Boch did not even consider changing Thanks to OVHcloud and VMware, Villeroy & Boch was able to its provider. “We’ve already been using OVHcloud Enterprise increase its performance significantly and thus achieve a shorter Support for two years. That lets us test new applications in a live time-to-market. “Every stakeholder has benefited from the environment and base investment decisions on the results,” Erik migration,” Heinen affirms. “We now get fewer support inquiries Heinen explains. “Enterprise Support is a must-have, because from the departments, which frees up resources and the total cost of ownership is what ultimately matters.” considerably reduces our management overhead.” The system OVHcloud initially tested the new PIM application in a clone is much more efficient: in e-shops such as Otto and Amazon, environment to explore the best way to implement it in the new customers find relevant product information faster and therefore system. The application is already yielding handsome benefits. have a firmer foundation for their purchase decisions. Heinen is Through this live test, Villeroy & Boch gained a comprehensive pleased: “At the end of the day, that pushes up our revenue. insight into all tools without any unpleasant surprises. This made And responsibility for the infrastructure stays in one pair of it clear to the ceramic producer what advantages the new hands.” technology would bring to the PIM application. “As the first Today, the company is reaping the rewards of lower costs and VMware VCPP (VMware Cloud Provider) partner in Europe, faster times to market for new products. Thanks to innovative OVHcloud gives its customers the opportunity to test latest solutions, the traditional ceramics producer from western VMware technologies. We are pleased to enable Villeroy & Germany has nothing to fear from its global competitors: its Boch’s entry into vSAN technology,” adds Khaled Allab. program of international expansion, focusing on new growth markets, can go ahead. Villeroy & Boch’s global presence and the further development of its brand are assured. Meanwhile, high availability of the services made available on the
Recommended publications
  • Rapport D'information Sur Les Géants Du Numérique
    N° 4213 ______ ASSEMBLÉE NATIONALE CONSTITUTION DU 4 OCTOBRE 1958 QUINZIÈME LÉGISLATURE Enregistré à la Présidence de l’Assemblée nationale le 2 juin 2021. RAPPORT D’INFORMATION DÉPOSÉ en application de l’article 145 du Règlement PAR LA COMMISSION DES AFFAIRES ÉTRANGÈRES en conclusion des travaux d’une mission d’information constituée le 20 novembre 2019 sur les géants du numérique ET PRÉSENTÉ PAR M. ALAIN DAVID ET MME MARION LENNE, Députés —— — 3 — SOMMAIRE ___ Pages INTRODUCTION ........................................................................................................... 7 SYNTHÈSE DES RECOMMANDATIONS DES RAPPORTEURS ............ 10 PREMIÈRE PARTIE : LE NUMÉRIQUE, OBJET ET TERRAIN GÉOPOLITIQUE DU XXI ÈME SIÈCLE ................................................................... 13 I. LES GÉANTS AMÉRICAINS DU NUMÉRIQUE, NOUVEAUX CONCURRENTS DES ÉTATS ? ............................................................................... 13 A. LA GENÈSE DES GAFAM : UNE HISTOIRE AMÉRICAINE .......................... 13 B. LES CARACTÉRISTIQUES DES GÉANTS AMÉRICAINS DU NUMÉRIQUE : DES ENTREPRISES HORS NORMES ................................... 17 1. Les cinq « GAFAM » présentent plusieurs caractéristiques communes mais aussi d’importantes spécificités ............................................................................. 17 2. Du numérique aux géants : le développement d’entreprises devenues systémiques, dont les activités se sont largement diversifiées ............................... 18 a. La théorie économique permet d’éclairer
    [Show full text]
  • Technology, Media & Telecom
    CLOUD MANAGED SERVICES AND HOSTING SECTOR REVIEW | Q1 2020 Technology, Media & Telecom Cloud Managed Services and Hosting| Q3 2020 TECHNOLOGY, MEDIA & TELECOM PAGE | 0 HW Cloud Managed Services and Hosting Solutions Introduction HARRIS WILLIAMS (“HW”) HW TECHNOLOGY, MEDIA & TELECOM (“TMT”) GROUP • 25+ years and more than 1,000 closed transactions • 35+ dedicated TMT professionals • 350+ professionals across eight office globally • TMT offices include Boston, San Francisco, and London • 170+ closed transactions in the last 24 months • 10 industry groups KEY TMT THEMES ✓SaaS / Cloud ✓Data & Analytics ✓Digital Transformation ✓A.I. / Machine Learning FOCUSED ADVISORY SERVICES HORIZONTAL FOCUS SECTORS VERTICAL FOCUS SECTORS • Mergers and acquisitions (M&A) • Application Software • Architecture, Engineering, and Construction Software • Capital raises • Cloud Managed Services and Hosting Solutions • Education Technology and Services • Corporate divestitures • Compliance Solutions • Energy Technology • CRM and Marketing Automation • Facilities and Real Estate Software • Human Capital Management • Financial Technology and Payments CONSISTENT RECOGNITION FOR QUALITY • Infrastructure and Security Software • Government Technology • IT and Tech-Enabled Services • Healthcare IT • Marketing, Research, and Insights Software • Industrial and Supply Chain Technology • Internet and eCommerce • Retail Technology HW CLOUD MANAGED SERVICES AND HOSTING SOLUTIONS TEAM OTHER TMT GROUP LEADERSHIP Thierry Monjauze Anthony Basmajian Priyanka Naithani Sylvain Noblet
    [Show full text]
  • GAIA-X: Technical Architecture Release – June, 2020 Imprint
    GAIA-X: Technical Architecture Release – June, 2020 Imprint Publisher Federal Ministry for Economic Affairs and Energy (BMWi) Public Relations Division 11019 Berlin www.bmwi.de Authors DE-CIX Management GmbH Günter Eggers (NTT Global Data Centers EMEA GmbH) Bernd Fondermann (German Edge Cloud GmbH & Co KG) Google Germany GmbH Berthold Maier (T-Systems International GmbH) Klaus Ottradovetz (Atos SE) Dr.-Ing. Julius Pfrommer (Fraunhofer IOSB) Dr. Ronny Reinhardt (Cloud&Heat Technologies GmbH) Hannes Rollin (T-Systems International GmbH) Arne Schmieg (German Edge Cloud GmbH & Co. KG) Sebastian Steinbuß (IDSA e. V.) Dr. Philipp Trinius (T-Systems International GmbH – Telekom Security) Andreas Weiss (EuroCloud Germany) Dr. Christian Weiss (Deutsche Telekom AG) Dr. Sabine Wilfling (Scheer GmbH) Current as at June 2020 Design and production PRpetuum GmbH, 80801 Munich You can obtain this and other brochures from: Federal Ministry for Economic Affairs and Energy, Public Relations Division Email: [email protected] www.bmwi.de Central ordering service: Tel.: +49 30 182 722 72 Fax: +49 30 181 027 227 21 This brochure is published as part of the public relations work of the Federal Ministry for Economic Affairs and Energy. It is distributed free of charge and is not intended for sale. The distribution of this brochure at campaign events or at information stands run by political parties is prohibited, and political party-related information or advertising shall not be inserted in, printed on, or affixed to this publication. Content 1
    [Show full text]
  • Cookbook-En.Pdf
    L'INFRASTRUCTURE # 1 CASE STUDIES BOOK DISCOVER ORIGINAL INFRASTRUCTURES DEPLOYED AT OVH.COM Online media, applications and business software, collaborative tools, smart music playlists at points of sale, total outsourcing of an urban community’s IT… OVH.com CASE STUDIES BOOK - EDITORIAL 3 “Each year, OVH is able to offer several hundred new services. After listening to you, we have come to realize that launching new services is not enough. We should also assist and guide you in the adoption of these innovations. Often you just need to see some practical use cases. That is the goal of the “Case Studies Book”, to provide you with such examples. And of course, if you need advice, our customer advocates and our Professional Services team are always available. Enjoy your reading!” Octave Klaba, Founder OVH CASE STUDIES BOOK CASE STUDIES BOOK This publication has been edited by the OVH Group, 2 rue Kellermann 59100 Roubaix (FRANCE) - RCS Lille Métropole 424 761 419 00045. Written by: Hugo Bonnaffé in collaboration with: Rémy Vandepoel, Vincent Cassé, Jean-Daniel Bonnetot, Félicien Lainé, Jonathan Guinez, Sylvain Wallez et Alexandre Morel. Translation: Michael Kapus Layout: Marie Delattre Graphic Design: Carl Lambert, Lucille Folens and Élodie Lenin Photographers: Élycia Husse, Frédéric Anne, Alban Gernigon, Stéphane Bureau du Colombier, iStockphoto Printer: Nord'imprim Special thanks is given to each customer that made this project possible by revealing the details of their infrastructures and their willingness to share their expertise with the OVH Community. Congratulations to everyone who took to the stage during the OVH World Tour to present their projects and explain their technical choices.
    [Show full text]
  • Achieving Digital Sustainability
    ACHIEVING DIGITAL SUSTAINABILITY RapportProgress report, d’étape, summary synthèseof collaboration of platformthe platform work and 11 Arcepde proposalstravail toand combine proposals increasing de use Arcepof digital technologypour andun reducing numerique its environmental soutenable. footprint — 15 December 2020 INTRODUCTION The impact that electronic communi- cations networks, devices, data centres and ICT use have on the environment is a source of growing concern, and one number of devices, etc.) is cause for con- which an increasing number of stake- cern. According to the Senate task force holders are gradually starting to address. on ICT’s environmental footprint6, digi- The Citizens’ Convention on Climate1 also tal technology’s GHG footprint could notes that while digital technology is a increase substantially if nothing is done crucial lever of the green transition, and to curtail it (+60% by 2040 or 6.7% of the battle against climate change, it must the national GHG footprint). If such an not itself be the source of increased emis- increase were to materialise, it would sions. be counter to the commitments made under the Paris Climate Agreement7 of According to various studies conducted 2015 which aims to contain the increase over the past two years2, digital tech- in global temperature to well below 2°C, nology currently represents 3% to 4% and requires swift and massive efforts from of global greenhouse gas3 4 (GHG) emis- every sector of the economy to reduce sions, and 2% of the carbon footprint in their own carbon footprint8. France5 (including the hardware pro- On top of which, there are other contrib- duction and usage stages).
    [Show full text]
  • GAIA-X: Technical Architecture Release – June, 2020 Imprint
    GAIA-X: Technical Architecture Release – June, 2020 Imprint Publisher Federal Ministry for Economic Affairs and Energy (BMWi) Public Relations Division 11019 Berlin www.bmwi.de Authors DE-CIX Management GmbH Günter Eggers (NTT Global Data Centers EMEA GmbH) Bernd Fondermann (German Edge Cloud GmbH & Co KG) Google Germany GmbH Berthold Maier (T-Systems International GmbH) Klaus Ottradovetz (Atos SE) Dr.-Ing. Julius Pfrommer (Fraunhofer IOSB) Dr. Ronny Reinhardt (Cloud&Heat Technologies GmbH) Hannes Rollin (T-Systems International GmbH) Arne Schmieg (German Edge Cloud GmbH & Co. KG) Sebastian Steinbuß (IDSA e. V.) Dr. Philipp Trinius (T-Systems International GmbH – Telekom Security) Andreas Weiss (EuroCloud Germany) Dr. Christian Weiss (Deutsche Telekom AG) Dr. Sabine Wilfling (Scheer GmbH) Current as at June 2020 Design and production PRpetuum GmbH, 80801 Munich You can obtain this and other brochures from: Federal Ministry for Economic Affairs and Energy, Public Relations Division Email: [email protected] www.bmwi.de Central ordering service: Tel.: +49 30 182 722 72 Fax: +49 30 181 027 227 21 This brochure is published as part of the public relations work of the Federal Ministry for Economic Affairs and Energy. It is distributed free of charge and is not intended for sale. The distribution of this brochure at campaign events or at information stands run by political parties is prohibited, and political party-related information or advertising shall not be inserted in, printed on, or affixed to this publication. Content 1
    [Show full text]
  • Télécharger Un Extrait
    LE RÔLE CENTRAL DES NOMS DE DOMAINE DAVID CHELLY Naming Start-up Référencement Nommage 1 Avant-propos Il est d’usage de démarrer un ouvrage en adressant ses remerciements à ses proches, puis d’inviter une ou plusieurs personnes de référence du secteur à écrire la préface, c’est-à-dire à passer la pommade à l’auteur pour son formidable travail. Cet ouvrage vous épargne ces conventions à l’utilité relative et vous invite dès à présent à un voyage dans l’étonnant monde des noms de domaine. Dans l’écosystème de l’internet, les noms de domaine occupent une place transversale. Ils sont utilisés par une multitude d’acteurs, depuis les webmasters indépendants jusqu’aux informaticiens, juristes et marketeurs dans les entreprises, en passant par les bureaux d’enregistrement, les agences web et les investisseurs en noms de domaine. C’est à l’ensemble de ces professionnels que s’adresse ce livre, avec l’ambition d’offrir une vision globale et transdisciplinaire des possibilités offertes par les noms de domaine. Cette problématique est particulièrement d’actualité, puisque l’on est passé en quelques années de moins de deux cent cinquante extensions de noms de domaine disponibles à plus de mille cinq cents aujourd’hui, ce qui pose une multitude de questions en termes de protection juridique, de référencement et de branding. Les étudiants spécialisés dans l’internet, les chercheurs d’emploi et les personnes en reconversion professionnelle pourront également trouver un intérêt à la lecture de cet ouvrage, dans le sens où les opportunités d’emploi sont considérables dans ce secteur en fort essor, mais peu abordé dans les programmes des formations académiques.
    [Show full text]
  • Premium Domain Sales Report
    2020 $320,136 PREMIUM DOMAINS Total premium revenue REPORT Premium Registrar RESULTS $203,884 Premium revenue 155 Premium domains sold $1315 Average price per domain sold Registrar market share per domains sold Alibaba Cloud Computing 18% Namecheap 10% GoDaddy 28% Google 5% Gandi 4% HEXONET 4% OVHcloud Others 3% 28% Registrar market share in terms of revenue HEXONET 18% Namecheap 9% GoDaddy West.cn 37% 7% $ Alibaba Cloud Computing 4% Google 3% Others 22% TOP 5 TOP 5 Premium tiers in terms of revenue Premium tiers in terms of domains sold 1st Tier $2500 1st Tier $100 2nd Tier $4000 2nd Tier $250 3rd Tier $1000 3rd Tier $2500 4th Tier $100 4th Tier $1000 5th Tier $250 5th Tier $500 Premium Brokerage RESULTS TOP 3 brokered premium domains 1st energy.cloud $50,000 $116,252 2nd power.cloud $24,360 Premium domain revenue 3rd simple.cloud $14,825 Why innovative companies choose premium .cloud domains power.cloud Powercloud is the fastest growing billing and CRM system in the energy industry. Therefore it was essential to have a strong brand identity and a domain name that stays in your head. As cloud-natives, we believe the domain power.cloud will support us on our way to becoming the digital leader in the energy industry. “ Marc Pion, Head of Marketing & Communications, powercloud GmbH ” What’s trending with .cloud Companies from all over the world and in all dierent sectors choose .cloud premium domains for their business. Digital Transformation logistics.cloud blue.cloud Consumer Applications ! tldr.cloud golf.cloud Cloud-based Service tera.cloud iam.cloud International Sites jupiter.cloud sigma.cloud All prices indicated in this report are retail prices (tiers excluded) If the registrar markup of EPP premium domains sold is unknown, we apply an estimate of 30% get.cloud Smart domain for modern business Copyright © 2021 - Aruba PEC S.p.A a Socio Unico - P.IVA 01879020517.
    [Show full text]
  • C. Les Bureaux D'enregistrement
    1 C. Les bureaux d’enregistrement 1. Qu’est-ce qu’un bureau d’enregistrement ? Un bureau d’enregistrement est une entreprise chargée d’enregistrer des noms de domaine auprès des registres, pour le compte de ses clients, qu’ils soient professionnels ou particuliers. Un bureau d’enregistrement proposant des noms de domaine sous les extensions génériques doit être accrédité par l’ICANN, dans le cadre d’une procédure onéreuse et compliquée. On en compte environ mille à travers le monde 1. Chacun peut toutefois s'improviser bureau d'enregistrement de noms de domaine, en devant revendeur affilié à un bureau d'enregistrement agréé. Les extensions nationales (FR, BE, CH, etc.) sont commercialisées par des bureaux agréés par le registre national, selon des conditions qui diffèrent selon les pays, mais généralement peu contraignantes. 2. Un marché ultra-concurrentiel Le secteur des bureaux d'enregistrement des noms de domaine est très concurrentiel, puisque chaque prestataire propose exactement le même produit. A l’image du leader mondial Godaddy, nombre de bureaux d'enregistrement internationaux proposent des prix très agressifs. Cette situation pèse fortement sur la rentabilité des 1 Au 1er avril 2020, il existait 2453 contrats d’accréditation avec l’ICANN, mais près de la moitié concernent une seule entreprise, HugeDomains, via ses bureaux d’enregistrement Dropcatch. 2 acteurs, d’autant que la multiplication des nouvelles extensions s’est accompagnée d’un grand nombre de reventes entre registres, de changements de prestataires techniques et de modifications de politiques de prix. En pratique, ceci complique la gestion des offres de la part des bureaux d’enregistrement, avec en sus des ventes en deça des niveaux attendus.
    [Show full text]
  • IDC Marketscape: Worldwide Public Cloud Infrastructure As a Service 2020 Vendor Assessment
    IDC MarketScape IDC MarketScape: Worldwide Public Cloud Infrastructure as a Service 2020 Vendor Assessment Deepak Mohan Andrew Smith Rachel Liu THIS IDC MARKETSCAPE EXCERPT FEATURES OVHCLOUD IDC MARKETSCAPE FIGURE FIGURE 1 IDC MarketScape Worldwide Public Cloud Infrastructure as a Service Vendor Assessment Source: IDC, 2020 Please see the Appendix for detailed methodology, market definition, and scoring criteria. September 2020, IDC #US46795720e IN THIS EXCERPT The content for this excerpt was taken directly from IDC MarketScape: Worldwide Public Cloud Infrastructure as a Service 2020 Vendor Assessment (Doc # US46795720). All or parts of the following sections are included in this excerpt: IDC Opinion, IDC MarketScape Vendor Inclusion Criteria, Essential Guidance, Vendor Summary Profile, Appendix and Learn More. Also included is Figure 1. IDC OPINION Public cloud infrastructure as a service (IaaS) is increasingly seen by organizations as the preferred infrastructure backbone for digital transformation (DX) initiatives and IT modernization. This is evidenced by the continued pace of growth in public cloud IaaS spending, which grew 38% in 2019 to a worldwide total of $49 billion. IDC estimates the enterprise IT spend on public cloud IaaS to exceed spend on traditional infrastructure and private cloud infrastructure systems within the next five years. The COVID-19 disruption has renewed the focus on flexibility and cost optimization, accelerating the usage of public cloud IaaS by enterprises. The rapid pace of public cloud IaaS adoption has resulted in a corresponding evolution of customer demands and offerings in this market. This includes increasing demand from traditional IT environments to facilitate easy adoption of public cloud IaaS, as well as a shift in customer preferences around where and how they want to adopt cloud.
    [Show full text]
  • View the Slides
    The Hijackers Guide To The Galaxy: Off-path Taking Over Internet Resources Tianxiang Dai, Philipp Jeitner, Haya Shulman, Michael Waidner German National Research Center for Applied Cybersecurity ATHENE Technical University of Darmstadt Fraunhofer Institute for Secure Information Technology SIT National Research Center for Applied Cybersecurity 1 Overview ➢ Digital resources and providers ➢ Taking over resource holders’ accounts ➢ Vulnerable customers ➢ Potential resource manipulations ➢ Vulnerable resources ➢ Countermeasures & Conclusions National Research Center for Applied Cybersecurity 2 Digital resources and providers Provider datasets RIRs AFRINIC APNIC ARIN Customers datasets Digital resource Digital LACNIC RIPE providers resources Registrars Godaddy Namecheap ▪ 75% of customers of Networksolutions enom RIRs (Local ISPs) name.com Alibaba Amazon Gandi Namesilo Google OVH ▪ 100K-top Alexa Cloud Amazon Azure Access to resources (IaaS) Alibaba Google IBM Tencent Oracle via SSO accounts DigitalOcean Linode IONOS Hostwinds OVHCloud Vultr CloudSigma Certificate IdenTrust DigiCert Authorities Sectigo GoDaddy GlobalSign National Research Center for Applied Cybersecurity 3 Attacking providers Taking over accounts from off-path ▪ Take over accounts via password recovery: How to poison cache? ▪ Poison DNS cache for victim domain ▪ On-path lookup interception ▪ Off-path: ▪ Trigger password recovery for victim domain ▪ BGP prefix hijacks ▪ Reset password and take over account ▪ Side channels ▪ IP fragmentation Vulnerable BGP sub- Side- Frag- providers
    [Show full text]
  • Arxiv:2012.01946V1 [Cs.CR] 3 Dec 2020
    Can I Take Your Subdomain? Exploring Related-Domain Attacks in the Modern Web Marco Squarcina1, Mauro Tempesta1, Lorenzo Veronese1, Stefano Calzavara2, Matteo Maffei1 1TU Wien, 2Università Ca’ Foscari Venezia Abstract known to web security experts, yet they do not capture the full spectrum of possible threats to web application security. Related-domain attackers control a sibling domain of their tar- get web application, e.g., as the result of a subdomain takeover. In this paper, we are concerned about a less known attacker, Despite their additional power over traditional web attackers, referred to as related-domain attacker [6]. A related-domain related-domain attackers received only limited attention by attacker is traditionally defined as a web attacker with an extra the research community. In this paper we define and quantify twist, i.e., its malicious website is hosted on a sibling domain for the first time the threats that related-domain attackers pose of the target web application. For instance, when reasoning to web application security. In particular, we first clarify the about the security of www.example.com, one might assume capabilities that related-domain attackers can acquire through that a related-domain attacker controls evil.example.com. different attack vectors, showing that different instances of The privileged position of a related-domain attacker endows it the related-domain attacker concept are worth attention. We for instance with the ability of compromising cookie confiden- then study how these capabilities can be abused to compro- tiality and integrity, because cookies can be shared between mise web application security by focusing on different angles, domains with a common ancestor, reflecting the assumption including: cookies, CSP, CORS, postMessage and domain underlying the original web design that related domains are relaxation.
    [Show full text]