Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Do the best you can.

Aye. While guaranteeing the information is absolutely gone is often impossible, you should at least do what you can make it more difficult to retrieve or be accidentally revealed.

> and encrypt the drives

If you are using VMs then full disk encryption within the VM will work just as well, and most cloud services can offer effectively the same thing with their containers.

You just have to be very careful with key management, which in some cases may be inconvenient (blocking restart until you intervene to provide keys, if you don't want them stored on or directly accessible by the same provider) depending on how paranoid you feel the need to be. Of course if you are truly paranoid, by character or by contractual necessity, keys in memory on shared infrastructure even temporarily could be an issue at which point you need "dedicated cloud" resource or colo/self-host for the affected parts of your apps/infrastructure.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: