3 ms·
Our post is regarding IaaS clouds in general and has nothing specifically to do with EC2 or any other particular vendor. It may be the case that EC2 does have s
by cloudsigma 16y ago
Our post is regarding IaaS clouds in general and has nothing specifically to do with EC2 or any other particular vendor. It may be the case that EC2 does have secure measures in place; I wonder how many of their customers can articulate them (or customers of other IaaS clouds for that matter)? We are merely raising an important issue. You can look at the many other posts we have on the other various aspects of security in the cloud of which this post forms the latest instalment regarding data storage.
"there are more efficient ways than encryption or "full sweep overwrite" to address this at the storage-level."
Your suggestion would be?
Kind regards,
Patrick
- cloudsigma 16y agoVukk, The issue there is more about tracking. You'd have to track every single block and return zero for any that hadn't been used/altered since drive creation. I'm guessing it would prove pretty costly in terms of latency for drive access after initial drive creation but its a good idea potentially. I'll pass it onto our technical guys as well to ask about its feasibility. Best wishes, Patrick
- moe 16y agoYour suggestion would be? See my reply above about using a loopback-file. It's a one-liner: dd if=/dev/zero of=/vols/customer123/vol234 seek=$SIZE bs=1 count=1 There's surely quite a few other ways to skin this cat (eventually arriving at the multi-tenancy features in proprietary SAN appliances), but this seems the most obvious one.
- vukk 16y agoSince we are not directly accessing the HDD, couldn't the virtualization layer say if(disk block not written before) return 0; and thus the customer wouldn't have to worry? Or is this too inefficient?