3 ms·
What does encryption at rest protect against with a Cloud provider? I assume the read credentials must ipso facto decrypt the object. So encryption at rest pr
by funstuff007 4y ago
What does encryption at rest protect against with a Cloud provider?
I assume the read credentials must ipso facto decrypt the object. So encryption at rest protects you against an inside job at AWS (smash and grab drives) or government confiscation. Am I thinking about this correctly?
- QuadrupleA 4y agoYeah - physical drive theft I think. I assume that's well locked down (and a crap shoot whose data someone'd get if they stole some drives) but nice to be protected I guess.
- voakbasda 4y agoI am thinking that it lowers their cost for recycling drives. If everything is encrypted at rest, you don’t need to go to crazy lengths to wipe the drives.
- majewsky 4y agoThis is it. I help maintain the object storage for a private cloud. Because we have LUKS, preparing servers for decommissioning is done in a matter of minutes (once the servers have been removed from the cluster configuration, of course). We only have to stop all server processes, unmount the disks, overwrite the LUKS headers with /dev/random. Then server management kicks the nodes out of the Kubernetes cluster, then data center management takes care of the hardware.
- oxymoron 4y agoWhen I started working for AWS as an SDE, I was hoping it’d be possible to visit a datacenter. I was surprised to find out that I’d require L11 (!) approval to so so! The only L11 in my reporting chain is Adam Selipsky. I’m told the AWS data centers has red zones, which no harddrive can be taken out of, without being mechanically and violently destroyed first.
- betaby 4y agoHow it's protects from government confiscation if key is also stored at AWS (most likely on a different server)? Please explain.
- funstuff007 4y agoYes, if AWS has possession of keys and drives and the govt wants the data, I cannot imagine how encryption at rest does anything for you.
- aaomidi 4y agoEncryption keys are kept physically and logically separate the majority of the time. Generally on HSMs that you can’t really read the private key from. It’s a huge improvement in security if one of their layers of defenses fails.