Researchers Find Amazon Cloud Servers Teeming With Backdoors And Other People's Data
Eurecom's researchers (from the left) Jonas Zaddach, Davide Balzarotti, and Marco Balduzzi — Renting a server from Amazon Web Services promises all the advantages of the Cloud: ephemeral …
Context & Ripple Effects
Amazon Web Services spent 2008 establishing itself as serious infrastructure — the AWS platform drew finalists like Knewton well beyond Web 2.0 video startups, and by January 2008 Amazon disclosed on its earnings call that Web Services was already consuming more bandwidth than Amazon.com itself. Renting ephemeral compute had become mainstream practice.
The story arrives months after an August 2011 EC2 outage knocked several high-trafficked sites offline, which Amazon said it resolved but which left reliability questions hanging. Eurecom researchers Jonas Zaddach, Davide Balzarotti, and Marco Balduzzi now add a second axis of concern: the rented machines themselves arrive carrying backdoors and residual data from other tenants.
First-order effects
- EC2 customers who spin up instances can inherit backdoors planted by previous occupants or find strangers' data still resident on the machines they just rented — a direct exposure for anyone treating a fresh instance as clean.
- Amazon faces a trust problem layered on top of the August outage: reliability concerns were about uptime, this finding is about whether the isolation between tenants holds at all.
Second-order effects
- Enterprise buyers weighing cloud migration against owning hardware gain a concrete security argument, pressuring AWS and rival providers to demonstrate tenant hygiene — image sanitization, provenance guarantees — rather than assume it.
- Security researchers get a new audit surface: if rented infrastructure carries artifacts of prior use, cloud forensics and pre-deployment scanning become services providers or third parties must offer.
Third-order effects
- If multi-tenant infrastructure routinely ships with inherited compromise, the industry's burden of proof shifts: providers will be expected to warrant what runs on their metal, making verifiable isolation a competitive feature rather than an assumption.
- The pattern points toward security economics reorganizing around the cloud layer itself — attackers and defenders both following workloads off corporate networks and onto shared infrastructure.
The trend: As computing moves onto rented multi-tenant infrastructure, security scrutiny follows the workloads — shifting from endpoint defense to auditing the cloud platforms themselves.