27 ms·
You raise a number of interesting points. Firstly we can't comment on the arrangements of other companies for whom we don't have visibility. As a customer you
by cloudsigma 16y ago
You raise a number of interesting points.
Firstly we can't comment on the arrangements of other companies for whom we don't have visibility. As a customer you can of course ask them and one would hope they are able to provide you with a full answer. On the blog we raise and answer (in our case) the various aspects for data storage, not just of security but also legal issues and data migration aspects. How many customers currently using an IaaS cloud can answer those questions or get their vendor to provide answers? Building confidence in cloud computing is all about transparency, education and creating secure ways of working. Different users will choose different solutions and regimes that they feel are 'secure' for them and we are all for that. We'd also like people to be able to make informed choices which means having the right information.
Secondly, there is a big difference between a vendor that has sole root access and full visibility of all your data and one that doesn't (as in our case); in our cloud the customer retains sole root access to cloud servers. This means our employees don't have visibility into cloud servers in the way you suggest. Further, as clearly stated in the blog, the issue raised is about data leakage i.e. data being accessible between cloud users. There are other issues regarding vendor security but this doesn't negate the points being made about data leakage.
Finally, your point regarding the encryption being a placebo is specious. There is a big difference between making systems secure against casual data theft/leakage or the actions of rogue employees and a company that is institutionally set up to lie and steal their customers' data. If you think your vendor is actually of that nature then no security measure can help and that's the case for any company you have dealings with. It really isn't a valid criticism of any security measure that may be put in place.
The measures we outline and have implemented on the vendor side do address the real issue of data leakage that occurs with block storage devices in IaaS clouds; they are effective and they are convenient. Our storage performance is generally higher than many other vendors to begin with and we have much feedback from customers regarding this even after using encryption. These customers are getting good performance in a secured cloud. For them it makes sense.
Best wishes,
Patrick
- moe 16y agoI can't help it, it just doesn't make sense to me. The only people it would theoretically protect me against are your people (those with physical access). And if I don't trust your people then why should I trust your encryption? The issue of data leakage between customers (who don't have physical access) seems so trivial to prevent to me that I'm honestly wondering if I'm missing something fundamental here. What's wrong with just making a loopback file and mounting that to the customer node? I had in fact assumed that this is how most clouds do it (for sanity reasons alone, security being the bonus). Hence I'm rather baffled by the whole claim of "data leakage through reading the raw volume". Has that ever happened on any cloud provider?
- cloudsigma 16y agoThe blog post looks at three main aspects to data storage: - keeping data private (to you as a user) - thinking about legal issues of location and control - thinking about migration issues Of the first point we outline how data leakage is possible in IaaS clouds. Some may already have measures in place to prevent this. We have our own measures too, some private others public. We offer encryption also as a free and convenient way to secure your data. This has nothing to do with securing physical access which is a totally separate issue. It relates to how customers secure access to their data. As outlined previously we don't have root access or file system level visibility into cloud servers in the way that other vendors generally do (although there are exceptions). As such it does pretty much come down to securing physical access. That isn't the case on other platforms for sure. Here's another article that you might like (short but sweet) which actually talks directly about EBS and others and the problem of 'data remanance' in a way we can't as a competing vendor: http://elastic-security.com/2010/01/07/data-remanence-in-the-cloud/ http://elastic-security.com/2010/01/07/data-remanence-in-the... Here's an interesting quote: "The technique of overwriting file sectors does not work without the collaboration of the cloud provider. You are not given access to the physical device, but only to higher level abstractions like file-systems (e.g. Amazon EBS) or key-value based APIs (e.g. Amazon S3). " I'll get back to you on the loopback technique once I've spoken with the relevant storage guys in our company for feedback. Kind regards, Patrick