Re: Cloud computing ( was Re: Linux Petition )
Andy Smith <[email protected]>
| Newsgroups | gmane.user-groups.linux.london.gllug |
|---|---|
| Message-ID | <[email protected]> |
Hello, On Sat, Apr 28, 2012 at 03:59:56PM +0100, JLMS wrote: > But one is supposed to be encrypting communications also (VPN, ssh, SSL, etc). > > I don't see what is left uncovered ... The keys for your encrypted data exist in the memory of the virtual machine, which is readable by whoever has access to the metal. I would say however that most attacks are simplistic and that encrypting data prevents a lot of the simple attacks. e.g. the recent Linode exploit where many tens of thousands of $ equivalent of bitcoins were stolen relied upon the attacker using a bug in Linode's web interface to shut the VPS down and reset its root password. That wouldn't have worked if the filesystems were encrypted and also would not have worked if the actual bitcoin data files were encrypted. Cheers, Andy -- http://bitfolk.com/ -- No-nonsense VPS hosting -- Gllug mailing list - [email protected] http://lists.gllug.org.uk/mailman/listinfo/gllug
signature.asc
(application/pgp-signature, 198 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEAREDAAYFAk+cMUwACgkQIJm2TL8VSQs9xQCgwDexjZtayivwcMB6g82hgOe8 UsAAnRkDXV+F6Pb22uzQg2EtYh0fLCoA =2BcB -----END PGP SIGNATURE-----