Maybe they mixed data from many companies on the same volume like S3 does. Maybe there were ACLs on that. Maybe it includes PII. Maybe it's a bunch of shards and needs an index on OSS servers to reassemble. Maybe it's encrypted by keys OSS had.
Maybe they mixed data from many companies on the same volume like S3 does. Maybe there were ACLs on that. Maybe it includes PII. Maybe it's a bunch of shards and needs an index on OSS servers to reassemble. Maybe it's encrypted by keys OSS had.
2. That doesn't actually seem to be Iron Mountain's argument here, though the reporting isn't crystal on the point.
There is no way for Iron Mountain to determine who OSS’s customers are, and their permissions, without help from OSS itself.
And because OSS is defunct, they can’t get that help.
How does AWS then determine which files are whose when my angry clients go knocking on their doors because I've decided to disappear?
2 it doesn't say either way. From owning systems like this, I'd assume there's some degree of "we have no idea what's in this bucket and can't just hand it over to random person asking for it".
Context: I owned a photo backup startup. 8.6 billion photos. Some might be yours, most are not. If you went to AWS and asked for a copy of the bucket, they rightfully wouldn't have complied.