4 ms·
> Data encryption at rest is a must-have for any modern Internet company What is it protecting against — data recovery from discarded old disks? Very stupid cr
by floatboth 7y ago
> Data encryption at rest is a must-have for any modern Internet company
What is it protecting against — data recovery from discarded old disks? Very stupid criminals breaking into the datacenter, powering servers off and stealing disks?
A breach in some web app would give the attacker access to a live system that has the encrypted disks already mounted…
- enitihas 7y agoI think mostly against breach in datacenter security. Most competent companies already have policies on how to deal with discarded old disks. The one that don't have might not be competent enough to use encryption on rest too. It's all about layers of defenses.
- mercora 7y agobeing able to purge old disks confidently in a secure manner is a upside huge enough to make this statement true in my opinion. There have been numerous incidents even involving companies specializing in securely purging disks. If your data is encrypted there is basically nothing to do you could even outright sell those from your DC or something. Just delete the keys/headers from the disk and you are safe. Its also not possible to get data injected offline into your filesystem without having the keys. Without encryption you could just get the disk of the targeted server running somewhere and set your implants or what you have. When the server sees the disk back up it looks just like a hiccup or something.
- brobinson 7y ago> Its also not possible to get data injected offline into your filesystem without having the keys. This is, in theory, possibly against volumes encrypted using AES XTS (which seems to the how the majority of FDE systems work) as the ciphertext is indeed malleable.
- mercora 7y agoi am no expert on this but i was thinking it is only possible to inject noise which is likely corrupting the filesystem in the process. copying/moving valid blocks should be prevented by XTS as far as i understood (which might not be that much). I guess using a filesystem with integrity checks helps a bit although its still not authenticated or something.
- brobinson 7y agoThere's some more details/links here (I'm also not an expert): https://en.wikipedia.org/wiki/Disk_encryption_theory#XTS_weaknesses https://en.wikipedia.org/wiki/Disk_encryption_theory#XTS_wea...
- zzzcpan 7y agoOn top of what others have said it protects, for example, from governments of all countries you have servers in and their law enforcement coming in taking the servers, extracting keys for mitm, installing malware and backdoors, placing some child porn on the servers, etc., from staff from various companies in various countries that maintains and deploys the infrastructure or just has access to it doing similar nasty things, and so on.
- toolslive 7y agoencrypted data at rest allows you to do an instant erase of the device.
- derefr 7y agoYes, the former. You can’t just put SSDs through a degausser!
- netcoyote 7y ago> criminals breaking into the datacenter, powering servers off and stealing disks? Yes, exactly. A company I worked for had a hard drive pulled from a running server in a (third party) data center that contained their game server binaries. Shortly afterwards as pirate company setup a business running “gray shards”, with - no surprise - lower prices.
- eastdakota 7y agoAs we push further and further to the edge — closer and closer to every Internet user — the risk of a machine just walking away becomes higher and higher. As a result, we aim to build our servers with a similar mindset to how Apple builds iPhones — how can we ensure that secrets remain safe even if someone has physical access to the machines themselves. Ignat's work here is critical to us continuing to build our network to the furthest corners of the Internet. Stay tuned for more posts on how we use Trusted and Secure Boot, TPMs, signed packages, and much more to give us confidence to continue to expand Cloudflare's network.