Live data from Hacker News

SSD belonging to Euro-cloud Scaleway was stolen,then turned up on YouTube

theregister.com

21–30 of 50 posts

Re: SSD belonging to Euro-cloud Scaleway was stolen,then turned up on YouTube

#21

The things that are not clear to me are: - Why was the disk being replaced (SMART warnings? HW upgrade? It failed in some way) - Why was the quick format recoverable? Was TRIM issued or the HW didn't support it? - As a follow up, I'm guessing the HW didn't support HW encryption? - Why are they relying on 3rd parties for the destruction of data? Meanwhile, it seems that HDs don't leave Google datacenters in one piece

The disk could be simply transferred to another data center physically so they can move data faster/cheaper than transferring the data by internet.

Re: SSD belonging to Euro-cloud Scaleway was stolen,then turned up on YouTube

#22
post #10

Earlier quoted context omitted.

There's a checkbox to encrypt the disks when installing some linux distros.

> There's a checkbox to encrypt the disks when installing some linux distros. While I'm not going to defend moving around unencrypted disks it is not as simple as that. The difficult part is not the encryption. The difficult part is the key management of the encryption. You need to solve issue like ensuring you don't lose access to the keys (and thereby access to the data), securely providing keys to people and machi…

I thought any of these providers always encrypted with their own key whether you encrypted on top of that or not. But I guess not.

Yet another reason to just stick with the big providers. They seem to have pretty serious compliance needs and encrypt no matter what. (Yet you should still encrypt your assets, but I believe they all encrypt their volumes anyway and have pretty strict policies on how to dispose this kind of hardware)

Re: SSD belonging to Euro-cloud Scaleway was stolen,then turned up on YouTube

#23
post #18
post #6

Earlier quoted context omitted.

Based on links in the other hackernews thread, it was quick-formatted, but a filesystem containing qemu disk images was recovered: [1] The YouTube video is in French without English CC subtitles, but there's screenshots of exploring what I assume would be one of the qcow images: [2] * 03:59 `/root/.ssh` with SSH id_rsa (private) keys, (public) authorized_keys and (hashed) known_hosts * 07:14 server binaries * 08:42 s…

>it was quick-formatted are there OSes that perform quick format without issuing TRIM command to the SSD? TRIM would vanish the data in less than 15 minutes.

Yes, 15 minutes is not 'quick' by most standards - quick formats take seconds, not minutes.

Re: SSD belonging to Euro-cloud Scaleway was stolen,then turned up on YouTube

#24
post #10

Earlier quoted context omitted.

There's a checkbox to encrypt the disks when installing some linux distros.

> There's a checkbox to encrypt the disks when installing some linux distros. While I'm not going to defend moving around unencrypted disks it is not as simple as that. The difficult part is not the encryption. The difficult part is the key management of the encryption. You need to solve issue like ensuring you don't lose access to the keys (and thereby access to the data), securely providing keys to people and machi…

When I ran a cloud provider, we used a hardware security module on storage systems which had public/private key pair which could be used to decrypt the header on the disk which contained a copy of the symmetric cipher key. Each header had the symmetric cipher key encrypted with multiple different public keys, including a fallback whose private key only existed in on paper in a vault.

Each system could reach out to other storage systems to ask them to use their private key to decrypt the header (for example if their hardware security module had failed), but in some configurations this would require an operator to intervene to enter in passphrase to unlock the hardware security module to authorize the action.

This means that:

1. The symmetric cipher key could always be recovered, even from paper backup

2. Having physical access to a disk or any set of disks did not allow you to read the data

3. Having physical access to a disk and a hardware security module did not allow you to read the disk (unless you knew the passphrase, which was always present, and user set)

4. Having physical access to disks, servers, and hardware security module may not allow you to read the data (in the more secure configuration where passphrases were not cached on disk -- but this meant that rebooting required an operator to manually enter the password at boot)

5. The set of valid public keys could be changed frequently (this was indeed automated and only the set of currently active hardware security modules could decrypt the current disk header)

Of course you could always short circuit this by making a copy of the symmetric key when you did have access (e.g., `dmsetup table --showkeys`) but without putting some more hardware in the fast/hot path that was unavoidable. The symmetric key could not easily be changed, without rewriting the entire disk (though since it was a storage system designed to accommodate multiple failures, this wasn't that hard, but we didn't do it automatically)

The hardware security modules we used were FIPS 140-2 validated and physically connected to the racks (though it would be possible to cut them away). It would also be possible to spy on the APDUs sent to the modules to capture the decrypted data, since there was not mutual authentication (it was in the works though).

Re: SSD belonging to Euro-cloud Scaleway was stolen,then turned up on YouTube

#26
post #9

Earlier quoted context omitted.

With the big cloud provides its a trivial checkbox. Can anyone speak to the effort in doing it at the OS level?

It is trivial in the Ubuntu installer.

It's not trivial when it comes to a server. Sure, you can tick that checkbox you'll enable encryption, but when you reboot you realize that you can't actually SSH in it, as it's waiting for a key to be entered on the physical console.

Entering (and managing) that key is the hard part.

Re: SSD belonging to Euro-cloud Scaleway was stolen,then turned up on YouTube

#27
post #24

Earlier quoted context omitted.

> There's a checkbox to encrypt the disks when installing some linux distros. While I'm not going to defend moving around unencrypted disks it is not as simple as that. The difficult part is not the encryption. The difficult part is the key management of the encryption. You need to solve issue like ensuring you don't lose access to the keys (and thereby access to the data), securely providing keys to people and machi…

When I ran a cloud provider, we used a hardware security module on storage systems which had public/private key pair which could be used to decrypt the header on the disk which contained a copy of the symmetric cipher key. Each header had the symmetric cipher key encrypted with multiple different public keys, including a fallback whose private key only existed in on paper in a vault. Each system could reach out to ot…

Is there anything on the consumer level like this?

Re: SSD belonging to Euro-cloud Scaleway was stolen,then turned up on YouTube

#28
post #27
post #24

Earlier quoted context omitted.

When I ran a cloud provider, we used a hardware security module on storage systems which had public/private key pair which could be used to decrypt the header on the disk which contained a copy of the symmetric cipher key. Each header had the symmetric cipher key encrypted with multiple different public keys, including a fallback whose private key only existed in on paper in a vault. Each system could reach out to ot…

Is there anything on the consumer level like this?

It was all made out of parts with standardized interfaces, so components could be consumer equipment.

I also used the same software on my laptop to encrypt it. It's nothing fancy, just using the dm-crypt kernel module and any kind of hardware security module that talks PKCS#11 (which is all of them); On my laptop I just used my existing smartcard (which I used to login to the system and remote systems).

The disk header was just text occupying the first 4MiB of the disk in 2 circular buffers similar to LVM (though 2 copies for redundancy).

Re: SSD belonging to Euro-cloud Scaleway was stolen,then turned up on YouTube

#29
The timeline of events in Scaleway's blog post is very dubious.

If the SSD was stolen over one year ago why do they only acknowledge it now?

In March 2021 [1] they were writing about how great their security was:

> We are proud of our data centers and their security. We consider that we have implemented the best solutions to protect your most valuable asset: your data. We are well aware of the huge responsibility this represents. There can be no compromises when it comes to your data.

Why were customers whose data was leaked only informed in June 2021? The delay of over 1 year is a huge GDPR issue.

The timeline of the incident from public sources:

21 May 2021: Micode tweets a screenshot of the directory listing [2]

26 May 2021: First video on the subject [3]

6 June 2021: Scaleway customer is notified their data was leaked [4]

21 July 2021: Second video on the subject [5]

24 July 2021: Third video on the subject [6]

24 July 2021: Scaleway releases a French blog post stating "Over a year ago, an SSD was stolen" [7]

Storing the data unencrypted is bad, but IMHO Scaleway's handling of the incident creates much bigger questions about their credibility.

[1] https://blog.scaleway.com/how-we-protect-your-data/

[2] https://mobile.twitter.com/Micode/status/1395640486715662336

[3] https://www.youtube.com/watch?v=vt8PyQ2PGxI

[4] https://www.lowendtalk.com/discussion/comment/3258386/#Comme...

[5] https://www.youtube.com/watch?v=aOBVZUL1iBA

[6] https://www.youtube.com/watch?v=xf_cKTlOYLo

[7] https://blog.scaleway.com/incident-securitaire-video-youtube...

Previous discussion: https://news.ycombinator.com/item?id=27957471

Re: SSD belonging to Euro-cloud Scaleway was stolen,then turned up on YouTube

#30
post #6
post #4

Apparently with plaintext customer data. > Lechelle said Scaleway worked with the YouTuber to recover the disk. The French-language video creator has written to Scaleway with assurances they have not copied the information contained on the disk. It is said some customer data was on the drive, unencrypted, including the source code and SSH keys of an Italian VPS provider.

Based on links in the other hackernews thread, it was quick-formatted, but a filesystem containing qemu disk images was recovered: [1] The YouTube video is in French without English CC subtitles, but there's screenshots of exploring what I assume would be one of the qcow images: [2] * 03:59 `/root/.ssh` with SSH id_rsa (private) keys, (public) authorized_keys and (hashed) known_hosts * 07:14 server binaries * 08:42 s…

Other thread mentioned: https://news.ycombinator.com/item?id=27957471
Post reply on HN