6 ms·
Stealing disks does happen, especially on-premise, which is where these policies originated. Also, sometimes there are mistakes with decommissioning old drives
by likecarter 4y ago
Stealing disks does happen, especially on-premise, which is where these policies originated.
Also, sometimes there are mistakes with decommissioning old drives, and you wouldn’t want your data discovered in a landfill somewhere.
- eloff 4y agoThe author is talking specifically about AWS. The odds that there is a mistake decommissioning the disk that leaves the data intact, times that somebody salvaged it from a landfill, times that they care about your data is basically zero. Which means a logical person should worry about everything else.
- im3w1l 4y agoWhat are the odds that some arranges for all those things to happen though? When you try to go after them they will have plausible deniability.
- eloff 4y agoThat’s an interesting attack vector. Bribe someone to replace the disk without wiping it, and be in a position to intercept it after that.
- DrRobinson 4y agoThis would require you or the person in the data center to know which customer is using which disk. And data isn't stored on just one disk, it's spread out over multiple disks and many customers have shards of data stored on the same disk. So even if this did happen, the would only get fragments of data.
- fnordpiglet 4y agoDisk management and destruction is largely automated. That’s extraordinarily unlikely.
- knorker 4y agoYou forgot to multiply by the millions of disks they presumably go through every year.
- eloff 4y agoYou don’t though. Your risk calculation is the same.
- rolenthedeep 4y agoI once bought a "new" hard drive off Amazon. The connectors looked suspiciously scratched up, like it had been used before. When I dug deeper, they had wiped the SMART data and the partition table, but it was absolutely full of readable data. I found clear text server logs indicating that this drive was in a backblaze center for several thousand hours.
- dexterdog 4y agoDid you report that to backblaze? I would think a bug bounty would be paid on something like that.
- Jensson 4y agoI'd worry they would sue for hacking to cover it up, dumber things has happened to nice developers who report vulnerabilities.
- brianwski 4y agoDisclaimer: I work at Backblaze, and I was here first. > I'd worry they would sue for... If you are referring to Backblaze, we're not going to "sue" anybody for anything. We (Backblaze) have dealt with a bunch of frivolous lawsuits (and patent trolls) over the years suing us, and OMG we're not going to instigate any lawsuits over some honest person legitimately reporting some issue and being helpful. It isn't going to happen. Our reputation is important to us. Not just for Backblaze: I'm saying the individuals that founded Backblaze and those people that work now here base our entire existence and careers and the number one marketing efforts at Backblaze are based around we are trying to be "the good guys" and transparent and acting like it. There is no possibly world where we try to suppress a screwup like this through legal means. That would be a PR debacle of epic proportions. If something went wrong, let's shine a spotlight on that cockroach and figure it out together. I'm not sure the exact drive we are all talking about, but my first guess would be a customer ordered a $189 "USB Restore" all their data shipped to them on an encrypted drive) and we (Backblaze) shipped the customer a USB restore drive and they are subsequently selling it (after copying their restore off of it) on the open market. If it is above 8 TBytes this is absolutely *NOT* the case and we should get to the bottom of it. Without lawyers mucking up the situation.
- kube-system 4y agoThey don't go into a landfill unless they're broken. Old drives that someone could still get the data off of end up on eBay.
- lokar 4y agoGoogle has very tight physical security (metal detectors, etc) and disks are either confirmed erased or shredded I assume aws is similar
- LammyL 4y agoGoogle mostly runs their own data centers. Amazon mostly rents space in commercial data centers with lots of different companies. Aws is probably pretty secure but likely less physically secure compared to Google if you get into the nitty gritty details.
- fnordpiglet 4y agoThis is false. Aws builds and operates their own data centers. The design and architecture of their data centers are highly standardized and an enormous amount of the build is fully automated. When they do lease they lease just a basic power and fiber build and they build their data center ontop of the base. Given how much custom equipment they run at the data center level it would be impractical to do anything that was collocated. But most data centers for aws, especially in Virginia, are on Amazon owned land. As far as I am aware the only collocations are in the satellite zones, outposts, and in peering locations. https://www.datacenterknowledge.com/archives/2017/01/18/who-leased-the-most-data-center-space-in-2016 https://www.datacenterknowledge.com/archives/2017/01/18/who-...