It's very hard with posts like this to understand the true reach of the problem: is this like having ssh with "password" as the password or is it something much less dangeroues. Is this something that could be exploited without Amazon team messing with the hypervisor providing your VM or something a third party can exploit? If this is a problem with Amazon then I think it's not a real problem for many people: it's in…
I disagree. It's possible to make good use of public infrastructure without handling any important secrets on public machines. Under certain threat models, you have to assume public infrastructure is vulnerable to coercion of the providers and side-channel attacks from co-tenants. As we are beginning to see, providers have the tools and processes to comply with coercive demands (RAM/disk dumps) and co-tenants can feasibly succeed in obtaining secrets via side-channel attacks.
Under models like this, public infrastructure is still useful for storing and routing encrypted information, enabling NAT traversal, and distributing signed material which can be authenticated at the client.