http://news.ycombinator.com/item?id=362082
Do you still think that's a good idea?
http://news.ycombinator.com/item?id=362082
Do you still think that's a good idea?
I'm asking if you think it'd be a better idea (from a security perspective) to keep customers on separate VMs. My understanding of this vulnerability is that it relies on several customers sharing a filesystem; if Heroku simply spawned a new instance (they're already running on EC2) for each customer, wouldn't this be mitigated?
Also, I was looking up info on Pivotal Tracker yesterday (after the announcement that they were going paid) and saw your comment.
For many applications it seems entirely possible to do better with a single multi-tenant app stack than you could with OS virtualization with the same service model. In particular, if, to get the same service model, you had to customize your OS virtualization stack, I'd tack sharply towards preferring a multi-tenant app stack.
I can easily get my head around auditing the Ruby interpreter and its deployment on a Unix host. I've done projects assessing custom virtualization solutions and they are gigantic and complex to test. I'm pretty sure interrupt timing isn't going to screw up Heroku, but that's a flavor of the kind of stuff you have to test with full virtualization.
Finally, I have to add: everything is going to have bugs. You can fully virtualize every customer and every app and you will still eventually be exposed to something bad. The measure of the team is how they handle the exposure, how they fix it, and what they learn from the experience to make the next one harder to find.
Yes, but that'd cost a ton more than what they're doing right now. Consider the number of apps that they are hosting at the free level right now. Offering private instances as an upsell might make some folks happy though.