Brightbox
  • Home
  • Pricing & Signup
  • Why Brightbox?
  • FAQs
  • Blog
  • Services
  • Support
  • About
  • Contact
Blog RSS feed
twitter_banner

Flickr


more images...

Recent Posts

  • Happy Birthday Debian!
    4 days ago
  • See you at RailsConf Europe 2008
    1 week ago
  • Baz joins the team
    1 week ago
  • Emergency Maintenance, 8th - 11th July 2008
    1 month ago
  • Ruby Security Vulnerabilities
    1 month ago

Archives

  • August 2008 (3)
  • July 2008 (1)
  • June 2008 (4)
  • May 2008 (4)
  • April 2008 (3)
  • March 2008 (3)
  • February 2008 (3)
  • January 2008 (4)
  • December 2007 (4)
  • November 2007 (3)
  • October 2007 (1)
  • August 2007 (7)
  • July 2007 (1)
  • June 2007 (3)

Popular tags

    • announcements
    • beta
    • dapper
    • launch
    • maintenance
    • network
    • pricing
    • rails hosting
    • ruby
    • ruby on rails
    • security
    • ubuntu
    • uk
    • upgrade
    • xen

Tag Cloud

announcements backport bandwidth beta branding brightbox brightbox gem brightbox team business cluster conference dapper datacentre design events geekup gem hardy launch leeds maintenance meetup mysql network notices offer packages passenger paypal performance plans pricing rails hosting ruby ruby on rails san security team tech ubuntu uk updates upgrade virtualisation xen

Posts tagged ‘data’

Secure virtual disk deletion - is your data safe? 4 Dec 07

Everyone knows the dangers of old hard disks being discarded with sensitive data still on them, but what about virtual disks? With so many virtual machine hosting services cropping up of late (hi!), have you ever wondered what happens to your data when you delete your virtual machine?

Usually your machine’s ‘partition’ is just a small part of a larger disk array; the partition is deleted and the space returned for the pool to be used by another virtual machine. This means, the next time someone buys a virtual machine with the same host, some of the blocks that made up your filesystem could end up making up their filesystem. The metadata will be wiped clean when the filesystem is formatted of course, so they won’t just see your files listed, but the blocks can still contain your data. It depends on how they’re managing their disks.

Homework: go buy a virtual machine somewhere and pipe the contents of your new disk through the strings command and look out for anything that isn’t yours (ssh root@newmachine "dd if=/dev/sda1 bs=1M | strings"). Extra credit if you don’t get thrown off your new host on the first day for maxing out the disk IO :)

So, you’re probably careful and securely wipe your sensitive data before you leave, phew. But disk space is virtualised too. The blocks that make up your disk might not all be in order or even all be on the same disk. With snapshots, your data may exist in duplicate too that you can’t even access. And what about if you bought extra disk space, then removed it?

At Brightbox we use Linux’s LVM implementation to manage disk space and these are problems we have to deal with and we take it seriously. All virtual machine disks are wiped at the block level when the machine is deleted or when a new machine is created. The only corner case we’re likely to run into is if a disk image is extended into space that had previously been used as a snapshot or as a disk that was shrunk. Luckily we don’t currently offer snapshots or disk shrinking but it’ll be something we’ll probably offer at some point, so we’ll have to address it then.

Posted 4 December 2007 by John Leach • 1 comment

data+ deletion+ disk+ leak+ nas+ san+ security+ virtualization+ wipe+ wiping+ xen


Recent blog posts

  • Happy Birthday Debian!
    4 days ago
  • See you at RailsConf Europe 2008
    10 days ago
  • Baz joins the team
    13 days ago
  • Emergency Maintenance, 8th - 11th July 2008
    about 1 month ago
  • Ruby Security Vulnerabilities
    about 1 month ago
  • Brightbox v2.0.2 Gem released
    2 months ago

Join our email list

Flickr (more...)

RSS feeds

Blog feed

Flickr feed

Recent Wiki updates

System Status feed




Brightbox Partners and Vendors

Terms & Conditions | Privacy | Site map | Wiki

Copyright © 2008 Brightbox Systems Ltd. All rights reserved