At no time was customer data "leaked" between accounts. This would require that a user not scrub their volume after destroying their server; in this instance data would be recoverable and should be considered not sensitive.
Is it just me, or is this contradictory? "Data wasn't leaked.. but if it was it was because you didn't check scrub, so it must not have been important." These are two completely different things. Even if the data was not sensitive, it could still be leaked between accounts (which is what happened here).
Kudos for committing to fixing the problem though.
A lot of the talk was theoretical and the examples run were I think all within a user's own space.
If not though, then you're absolutely right that those are contradictory. If, even during disclosure, one user's data was made available to another user, that constitutes a data leak.
These are some of the strings I pulled off the root blockdev
- I have no such /var/deploy/chegou, or any of these files. I was
able to recover someone else's webserver logs from yesterday, as well.
Right now, as far as I can tell, that's speculative on both sides. Simply not enough evidence to say without corroboration that it's factually incorrect.
Comments
At no time was customer data "leaked" between accounts. This would require that a user not scrub their volume after destroying their server; in this instance data would be recoverable and should be considered not sensitive.
Is it just me, or is this contradictory? "Data wasn't leaked.. but if it was it was because you didn't check scrub, so it must not have been important." These are two completely different things. Even if the data was not sensitive, it could still be leaked between accounts (which is what happened here).
Kudos for committing to fixing the problem though.
A lot of the talk was theoretical and the examples run were I think all within a user's own space.
If not though, then you're absolutely right that those are contradictory. If, even during disclosure, one user's data was made available to another user, that constitutes a data leak.
https://github.com/fog/fog/issues/2525
https://f.cloud.github.com/assets/408977/1820859/8658298e-71...
Yep, in that case that's absolutely a leak of user data.
The blog post is factually incorrect on that point, what a shame.
Right now, as far as I can tell, that's speculative on both sides. Simply not enough evidence to say without corroboration that it's factually incorrect.