Re: Cloud computing ( was Re: Linux Petition )

Andy Smith <[email protected]>
Newsgroups gmane.user-groups.linux.london.gllug
Message-ID <[email protected]>
Hello,

On Sat, Apr 28, 2012 at 03:59:56PM +0100, JLMS wrote:
> But one is supposed to be encrypting communications also (VPN, ssh, SSL, etc).
> 
> I don't see what is left uncovered ...

The keys for your encrypted data exist in the memory of the virtual
machine, which is readable by whoever has access to the metal.

I would say however that most attacks are simplistic and that
encrypting data prevents a lot of the simple attacks.

e.g. the recent Linode exploit where many tens of thousands of $
equivalent of bitcoins were stolen relied upon the attacker using a
bug in Linode's web interface to shut the VPS down and reset its
root password. That wouldn't have worked if the filesystems were
encrypted and also would not have worked if the actual bitcoin data
files were encrypted.

Cheers,
Andy

-- 
http://bitfolk.com/ -- No-nonsense VPS hosting

--
Gllug mailing list  -  [email protected]
http://lists.gllug.org.uk/mailman/listinfo/gllug
signature.asc (application/pgp-signature, 198 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEAREDAAYFAk+cMUwACgkQIJm2TL8VSQs9xQCgwDexjZtayivwcMB6g82hgOe8
UsAAnRkDXV+F6Pb22uzQg2EtYh0fLCoA
=2BcB
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.