Home / Companies / DigitalOcean / Blog / May 2015

May 2015 Summaries

2 posts from DigitalOcean

Filter
Month: Year:
Post Summaries Back to Blog
The DigitalOcean platform has announced a security vulnerability, CVE-2015-3456, also known as VENOM, in its KVM/QEMU virtualization environment. This bug could potentially exploit a VM's virtual floppy driver and was identified by the company through a thorough audit of its platform. To mitigate the issue, DigitalOcean is rolling out updates across all infrastructure to apply the latest QEMU security patches and has implemented additional security features, including mandatory access control profiles for the QEMU process on hypervisors running the latest version of the cloud. A small number of hypervisors may require a reboot to complete the process, which will be done in a manner that minimizes disruption.
May 12, 2015 212 words in the original blog post.
DigitalOcean has published its first ever Transparency Report, which provides information on government data requests received by the company. The report shows that less than 0.05% of DigitalOcean's users have had their data requested, and the company frequently rejects broad or inadequately authorized requests. This move is part of DigitalOcean's policy to comply with law enforcement requests only when legally compelled, while also standing with its users in protecting their content. The report will be published semi-annually and provides a detailed look at how the company processes law enforcement requests, as well as additional resources for learning more about digital privacy.
May 11, 2015 334 words in the original blog post.