You're being ridiculous. They made a conscious decision to increase performance and the lifetime of their SSD drives by turning `scrub` off by default. If you enjoy DigitalOcean's prices (starting at $5), there must be some balance and optimizations to continue to run a business.
In the control panel, its quite clear, and easy to simply check scrub on. I agree that this change on the API front should have been articulated. However, Moisey acknowledge their mistake, let's move past it.
And yet all the other major VPS/cloud server providers have engineered solutions that do not suffer from this issue (regardless of physical storage medium). Specifically, Amazon, Linode, and Rackspace all have automatic mitigations (in varying forms) that prevent this type of leak.
No one would intentionally make the choice of having their data shared with other users, and if that is a business model they rely upon they need to find another.
This is a profound, never-ever-should-happen gap in data security, and it is yet another instance where DigitalOcean comes out looking remarkably amateurish.
Conversationally, I would have expected their hypervisor to have been doing thin provisioning: That until you write data to a block the block is 0s (having no provisioning on actual storage). And if you write 0s, that too isn't actually provisioned on real storage. And when you write actual data, well that is what the block now contains.
No one would intentionally make the choice of having their data shared with other users, and if that is a business model they rely upon they need to find another.
Unless they do not care if their data is shared, and would be willing to let it be shared for a reduced cost.
If there were a box that said "share your data" that you had to click, I cannot imagine the users who would click it. Further no one was ever told that the value proposition of DigitalOcean relies upon a complete and utter lack of data integrity.
That is a dishonest angle. It is not in any way how this has been sold. Further you don't get a discount for choosing not to scrub, but instead essentially get tricked into it by the magical law of defaults.
I do not mean to say that it was justified in this particular case. I was responding to the idea that all products must be secure, even for users who do not want to pay for the added security. Also, it is not so much that I think a service should offer a discount for handling your data insecurely (although in this particular case, the insecure handling is actually cheaper on a per user basis). Rather, there is a place in the market for products that are not secure, and therefore do not have to pay to develop and maintain the security aspects of the service.
Comments
You're being ridiculous. They made a conscious decision to increase performance and the lifetime of their SSD drives by turning `scrub` off by default. If you enjoy DigitalOcean's prices (starting at $5), there must be some balance and optimizations to continue to run a business.
In the control panel, its quite clear, and easy to simply check scrub on. I agree that this change on the API front should have been articulated. However, Moisey acknowledge their mistake, let's move past it.
No. It's not ridiculous. What's ridiculous is that they're even trying to claim no data was leaked when it demonstrably was.
There are many ways to securely scrub an SSD without subjecting it to a full write. They were outlined in the original thread.
This has nothing to do with scrubbing, or SSDs. This has to do with them providing my data to third parties without my consent.
They've leaked customer data between VMs. Their claims that this isn't true are false. Look at the screenshots!
Customers should not be able to access other customers' data under any circumstances.
And yet all the other major VPS/cloud server providers have engineered solutions that do not suffer from this issue (regardless of physical storage medium). Specifically, Amazon, Linode, and Rackspace all have automatic mitigations (in varying forms) that prevent this type of leak.
No one would intentionally make the choice of having their data shared with other users, and if that is a business model they rely upon they need to find another.
This is a profound, never-ever-should-happen gap in data security, and it is yet another instance where DigitalOcean comes out looking remarkably amateurish.
Conversationally, I would have expected their hypervisor to have been doing thin provisioning: That until you write data to a block the block is 0s (having no provisioning on actual storage). And if you write 0s, that too isn't actually provisioned on real storage. And when you write actual data, well that is what the block now contains.
Unless they do not care if their data is shared, and would be willing to let it be shared for a reduced cost.
If there were a box that said "share your data" that you had to click, I cannot imagine the users who would click it. Further no one was ever told that the value proposition of DigitalOcean relies upon a complete and utter lack of data integrity.
That is a dishonest angle. It is not in any way how this has been sold. Further you don't get a discount for choosing not to scrub, but instead essentially get tricked into it by the magical law of defaults.
I do not mean to say that it was justified in this particular case. I was responding to the idea that all products must be secure, even for users who do not want to pay for the added security. Also, it is not so much that I think a service should offer a discount for handling your data insecurely (although in this particular case, the insecure handling is actually cheaper on a per user basis). Rather, there is a place in the market for products that are not secure, and therefore do not have to pay to develop and maintain the security aspects of the service.