Scaleway: Incident SSD was stolen during a secure transport between datacenters
blog.scaleway.com
blog.scaleway.com
Scaleway did not publish their blog post until after the 3 part video series by Micode, despite being aware of the incident since May 2021. [2]
[1] https://www.lowendtalk.com/discussion/172819/scaleway-ssd-wi...
1. French YouTuber Micode bought a used SSD from leboncoin.
2. Micode wanted to demonstrate that data should always be properly wiped from used drives.
3. The SSD Micode obtained had been quick-formatted and was never encrypted, so it was trivial to recover the data on it.
4. Micode asked his followers on Twitter to try to identify the source of the drive.
5. It was eventually identified as belonging to Scaleway, and it contained important data from a Scaleway customer’s VM, including an SSH key, source code, and an S3 secret.
6. Scaleway threatened Micode, who now claims to have wiped the data.
7. Scaleway published a blog post claiming the drive was stolen while being transported between datacenters.
Unless I’m missing something that was lost in translation, I call bullshit on #7. They also seem to be claiming customers were notified immediately, but it that doesn’t appear to be the case. This just seems like they sold an old drive that should’ve been encrypted (it wasn’t) and wiped (it wasn’t). Whether that sale was authorized is a matter of debate—one former employee said they wouldn’t be surprised if someone just decided to walk out of the building with decommissioned hardware.
I find that unlikely ( unless as you said it was a rogue employee) - they're certified HDS ( hosting healthcare data) so i find it improbable they aren't supposed to have a special disk decommissioning process to follow, including secure wiping.
The 3-pass shred was done on the virtual disk each time a client left, and was done on the physical during maintenance.
[edit] And concerning encryption, it was at a premium, and i think only one of our client asked for it (this had a few issue). "hot" logs where not encrypted, but during the logrotation we tried to implement this (this was not technically audited btw, i think it was OK for Deloitte not to see our code)
Who here hasn't taken decommissioned or unneeded work computer crap home?
At work I recently replaced four 2.5" WD black 500GB spinning rust disks in Dell mini computers with m.2 SSDs. Since we are moving all of our systems to SSDs the WDs were trash but perfectly working with only a few months of time on them. I took the disks home and used them to play with FreeBSD and NetBSD on my Lenovo laptop. I didn't wipe them before taking them home either...
As for the other things, at the end of the 2nd video he did succeed on extracting and gaining access to the data, with full code source, AWS and Facebook (bot account) credentials (among others).
The exploration of the (redacted) data is in part 3
Edit: seems like the blog itself can be read in English with the button at the bottom, yet the articles themselves aren't necessarily translated after clicking on it. Localization is hard.
So we can conclude that it was not. If the disk was encrypted (with decent passphrase/key) there is 0% chance that the article wouldn't mention it.
They also wouldn't have bothered to get the disk back from the YouTuber. Why would they if the data is unreadable anyway?
I may be wrong of course. But would gladly know more info, if anyone has it.
It's in French though
[0]: https://web.archive.org/web/20210531091659/https://twitter.c...
[1]: https://www.youtube.com/watch?v=vt8PyQ2PGxI
[1] https://databasearchitects.blogspot.com/2021/06/what-every-p...