Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The cloud provider has physical access to the machines. They may have software access to the machines.

I'm sure they're contracted not to do anything bad, but there is risk of an insider incident at the cloud provider leading to an incident the customer can't prevent.



Encryption?


Doesn't help if the provider snapshots the ram containing the keys.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: