3 ms·
Encrypt all person-specific data with the a key unique to that person, and if the person requests deletion, delete the key. This effectively deletes all backups
by tyler_larson 9y ago
Encrypt all person-specific data with the a key unique to that person, and if the person requests deletion, delete the key. This effectively deletes all backups.
- mappu 9y agoHelp me understand - that seems like it just centralizes the problem. Since the key is now PII-equivalent, how is the key storage backed up?
- the_mitsuhiko 9y agoRevolving backups and you throw away old ones. After 30 days or so theast traces of a customer’s keys will be gone.
- mappu 9y agoIn that situation, the data is "inaccessible" but a data breach during the backup retention period will still leak their details. We can already achieve that result by removing records from the live DB and ignoring the whole backup situation. So what has this separate encryption process achieved?
- the_mitsuhiko 9y agoIt has achieved that within a time frame PII of a user are removed from backups.