It's interesting that this does not encrypt at rest (e.g., via dm-crypt). I'd rather not rely on Digital Ocean to protect access to their backups and prevent data from leaking to other droplets. Also, it requires a somewhat sophisticated attack to obtain the dm-crypt key from a running VM.
Comments
It's interesting that this does not encrypt at rest (e.g., via dm-crypt). I'd rather not rely on Digital Ocean to protect access to their backups and prevent data from leaking to other droplets. Also, it requires a somewhat sophisticated attack to obtain the dm-crypt key from a running VM.
https://news.ycombinator.com/item?id=6983097 https://www.digitalocean.com/company/blog/transparency-regar...