6 ms·
Encryption is an "addressable implementation" in the final Security Rule [1]. Practically this means you are not required to encrypt your data (e.g., between LB
by nkrumm 8y ago
Encryption is an "addressable implementation" in the final Security Rule [1]. Practically this means you are not required to encrypt your data (e.g., between LB and VM) "if the entity decides that the addressable implementation specification is not reasonable and appropriate [...]".
https://www.hhs.gov/hipaa/for-professionals/faq/2001/is-the-use-of-encryption-mandatory-in-the-security-rule/index.html https://www.hhs.gov/hipaa/for-professionals/faq/2001/is-the-...
- jontro 8y agoAnd also it looks like it supports encrypted traffic between the LB and the instance as shown in the guide.
- e1g 8y agoAWS LB does not validate backend certificates, so you can put a self-signed cert on the instance. Heck, even if the cert expires it will still work, and make LB<->EC2 connection technically encrypted. Yay compliance.
- xyzzy123 8y agoYou can actually turn this on (for classic ELBs), but it locks to a specific cert (rather than a CA). So yeah no one cares about expiry but the backend does have to present that cert. The thing to look for is "Enable backend authentication". I would question whether this is a problem though; basically if someone is in a position to MITM traffic in your AWS VPC this would indicate a compromise of AWS at a fundamental level (or loss of your AWS control plane).
- e1g 8y agoAWS does not encrypt internal traffic, including traffic between Availability Zones. AZ's are spread over several datacenters, so your VPC traffic (RDS/microservicers etc) travels unencrypted across multiple physical locations. I consider AWS network assurances sufficient so it's not a problem for our standard threat model, but the auditors got their checkboxes to tick...
- ec109685 8y agoDo you have a citation that data travels among data centers in aws unencrypted? At least between regions, it is encrypted: https://aws.amazon.com/blogs/aws/new-almost-inter-region-vpc-peering/ https://aws.amazon.com/blogs/aws/new-almost-inter-region-vpc...
- illumin8 8y agoIn case this sounds bad for security reasons (using self-signed certs) keep in mind that the VPC network does not allow clients to spoof IP addresses or receive traffic destined for any other MAC/IP pair. So, there is no need to validate the authenticity of a host on the network because it has already been validated by the VPC software defined network, and spoofing MAC/IP, or ARP poisoning, or any of the other traditional physical network layer attacks just don't work.
- gregwebs 8y agoHowever, it is required by AWS when you sign their BAA to have HIPAA compliance. The approach I looked at to solving this problem was using an Envoy proxy sidecar.