4 ms·
I wonder if the real reason for encrypting is that it allows cheaper deletion. You can save the IO of deleting an entire file and just delete the encryption key
by advisedwang 4y ago
I wonder if the real reason for encrypting is that it allows cheaper deletion. You can save the IO of deleting an entire file and just delete the encryption key. (aka cryptographic erasure, see [1])
[1] https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r1.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.S...
- throwaway320498 4y agoNot this. A customer's bytes are likely spread across millions of hard drives. At the filesystem layer, the region of the disk those bytes occupied still need to be reclaimed. What you're describing makes sense for a service like EBS where a single customer's bytes are limited to small number of disks in well-defined locations.
- hdjjhhvvhga 4y agoOne problem with utilizing unencrypted drives is that if there's a hardware failure, it's more expensive to dispose of them. Normally Amazon overwrites the data, degausses the drive and then destroys it, but if, say, the electronics is faulty, the first step becomes more difficult.
- gregw2 4y agoMy speculation is that they now have nitro encryption on all or enough of the servers supporting s3 so it’s now no marginal cost for them anymore since it’s inline ASIC encryption and not taking incremental CPU cycles anymore.
- severino 4y agoThis also implies that if the encryption key is that easy to dispose of, then it's also easy to somehow lose or screw it turning your valuable client data into a random stream of bytes, doesn't it?
- advisedwang 4y agoThey can dispose of it in the same way that they dispose of the actual core data (ie write over it X times, and ensure when disk is EOL that it's shredded). With cryptographic erasure you can do exactly the same erasure process on fewer bytes and get the same effective results.