4 ms·
I am neither the authority to define "encryption at rest", nor am i saying "encryption at rest" is good wording in this case. But from my understanding, "encry
by jand 5y ago
I am neither the authority to define "encryption at rest", nor am i saying "encryption at rest" is good wording in this case.
But from my understanding, "encryption at rest" is not disk encryption.
If you have a database with disk encryption, once the disk crypto key is entered an attacker could try to "do hacker stuff" and exfiltrate the WAL files.
If you have "encryption at rest", the WAL files are written encrypted and are decrypted on read. An attacker may get your WAL files, but they are still encrypted.
- Thorrez 5y agoThere are likely multiple definitions. This Azure definition disagrees with you: >Encryption at rest is designed to prevent the attacker from accessing the unencrypted data by ensuring the data is encrypted when on disk. If an attacker obtains a hard drive with encrypted data but not the encryption keys, the attacker must defeat the encryption to read the data. https://docs.microsoft.com/en-us/azure/security/fundamentals/encryption-atrest https://docs.microsoft.com/en-us/azure/security/fundamentals... So with this definition encryption at rest has the threat model of an attacker who can physically steal a hard drive but not the hard drive's encryption key.