DigitalOcean - Transparency Regarding Data Security
digitalocean.com
DigitalOcean - Transparency Regarding Data Security
1–10 of 17 posts
Re: DigitalOcean - Transparency Regarding Data Security
#2Re: DigitalOcean - Transparency Regarding Data Security
#3Is it just me, or is this contradictory? "Data wasn't leaked.. but if it was it was because you didn't check scrub, so it must not have been important." These are two completely different things. Even if the data was not sensitive, it could still be leaked between accounts (which is what happened here).
Kudos for committing to fixing the problem though.
Re: DigitalOcean - Transparency Regarding Data Security
#4Re: DigitalOcean - Transparency Regarding Data Security
#5Re: DigitalOcean - Transparency Regarding Data Security
#6And they forgot to add a date on their security updates. How are you supposed to know when issues are discovered and subsequently addressed?
Re: DigitalOcean - Transparency Regarding Data Security
#7At no time was customer data "leaked" between accounts. This would require that a user not scrub their volume after destroying their server; in this instance data would be recoverable and should be considered not sensitive. Is it just me, or is this contradictory? "Data wasn't leaked.. but if it was it was because you didn't check scrub, so it must not have been important." These are two completely different things.…
If not though, then you're absolutely right that those are contradictory. If, even during disclosure, one user's data was made available to another user, that constitutes a data leak.
Re: DigitalOcean - Transparency Regarding Data Security
#8I've seen the TRIM recommendation pop up a few times, and never with a reply from DO - is this probably how they're going to handle this, or is there a possible reason for not using TRIM?
Re: DigitalOcean - Transparency Regarding Data Security
#9I've seen the TRIM recommendation pop up a few times, and never with a reply from DO - is this probably how they're going to handle this, or is there a possible reason for not using TRIM?
If that's how they implement it, then I look forward to reading their future security advisory.
Re: DigitalOcean - Transparency Regarding Data Security
#10At no time was customer data "leaked" between accounts. This would require that a user not scrub their volume after destroying their server; in this instance data would be recoverable and should be considered not sensitive. Is it just me, or is this contradictory? "Data wasn't leaked.. but if it was it was because you didn't check scrub, so it must not have been important." These are two completely different things.…
A lot of the talk was theoretical and the examples run were I think all within a user's own space. If not though, then you're absolutely right that those are contradictory. If, even during disclosure, one user's data was made available to another user, that constitutes a data leak.
https://f.cloud.github.com/assets/408977/1820859/8658298e-71...
These are some of the strings I pulled off the root blockdev
- I have no such /var/deploy/chegou, or any of these files. I was
able to recover someone else's webserver logs from yesterday, as well.