25 ms·
> The argument that "you trusted this server enough to connect to it and download a file, therefore you clearly should trust it enough to permit it to execute a
by nathan_long 8y ago
> The argument that "you trusted this server enough to connect to it and download a file, therefore you clearly should trust it enough to permit it to execute arbitrary executables on your machine" is false in both cases.
Great point. Also, imagine that you control the server and you know that it was compromised. Surely you want to be able to download logs and other files from it for inspection without having your own machine compromised.
- toyg 8y ago> Surely you want to be able to download logs Uhm, nope: you want to shut it down and perform forensics on the disk. Once it's rooted, I wouldn't touch it with a barge pole.
- XCabbage 8y agoI've been a web developer for over 5 years and never once worked somewhere where I'd have any imaginable way of physically accessing the disk of a server. Everything's been cloud-based. I don't know the exact ratios, but I'd expect my experience not to be unusual.
- detaro 8y agoYou can't physically access the disk, but you often can download a snapshot or disk image, which is created at the hypervisor level.
- organsnyder 8y agoYou should still access that data in an offline manner, though—ideally: 1. Shut down the instance 2. Connect the storage as secondary storage on another (disconnected from the network) instance 3. Do forensics using your cloud provider's out-of-band management interface 4. Throw away that instance as soon as you're done
- deleted 8y ago[deleted]
- spenczar5 8y agoEvery cloud provider out there would help you get an image of the disk if you told them it was due to a security breach.