4 ms·
This does not necessarily imply that the data is unencrypted at rest. The query tool or the query backend could handle decryption seamlessly. S3 offers similar
by azurelogic 9y ago
This does not necessarily imply that the data is unencrypted at rest. The query tool or the query backend could handle decryption seamlessly. S3 offers similar encryption at rest that is invisible to authorized requesters. If the story was that someone raided an Apple data center, stole hard drives, and leaked customer data, then we would have reason to assume that.
- chatmasta 9y agoI assumed "encrypted at rest" to mean encrypted with the user's passcode, meaning it could only be decrypted from a properly authorized user session, not some internal apple tool.
- izuchukwu 9y agoFrom my understanding, that is how Apple encrypts on device. They don't use this with iCloud data at rest and instead maintain encryption keys themselves [1] so in the event of, for example, a user losing their credentials, they would still be able to assist. [1]: https://support.apple.com/en-us/HT202303 https://support.apple.com/en-us/HT202303
- andai 9y ago> Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if Apple could not help them out. From Darthy's comment 30 minutes ago https://news.ycombinator.com/item?id=14513803 https://news.ycombinator.com/item?id=14513803
- tsukaisute 9y agoAlways wondered that about encryption at rest as a feature in cloud services. The key is stored in the same system somewhere (or your app wouldn't function). A rogue employee can find the key if they want. So what is the practical benefit?
- ThrustVectoring 9y agoAFAIK, encryption at rest protects against a very specific threat. That is, someone goes into the data center, turns off your server, and steals the hard drive.