4 ms·
I understand that but I guess my question is other than another layer of access control to prevent mistakes, what am I actually getting. I know AWS has fixed t
by davewritescode 4y ago
I understand that but I guess my question is other than another layer of access control to prevent mistakes, what am I actually getting.
I know AWS has fixed this now, but in years past we paid a ton of money in KMS requests from s3 for these types of configurations and we asked ourselves what is this really buying us?
At the end of the day I have to assume some AWS employees have access to some or all keys in KMS.
- colmmacc 4y agoNo AWS employee has access to the keys directly from KMS. It's a hermetic system with no operator access like that. KMS Keys are released to AWS services for use based on IAM permissions and grants, and a time-bounded cryptographic pattern we call Forward Access Sessions ... where we end-to-end verify that the requesting service has a recent and legitimate signed request from the customer. KMS also has the capability to support an external trust store (https://aws.amazon.com/about-aws/whats-new/2022/11/aws-kms-external-key-store/ https://aws.amazon.com/about-aws/whats-new/2022/11/aws-kms-e...) ... where AWS holds no key material at all.
- aborsy 4y agoIt’s a bit like saying I don’t have access to keys in my Yubikey. Sure, but I can decrypt data with those keys. If I’m right, S3 sends encrypted data encryption keys to KMS, and KMS sends back the decrypted data encryption keys. So, although S3 has no access to the master key, it has access to the data keys in RAM for the customer to use. With a “bucket key,” it goes further storing those type of keys in disk.
- colmmacc 4y agoIt's more than what a Yubikey typically does. There are also can't-be-bypassed audit logs of the key usage, and the manner in which S3 is granted access to the data encryption key is very fine-grained; KMS won't allow the S3 systems to decrypt just anything. The key is stored in memory while it's being used to encrypt/decrypt, that's unavoidable, but humans don't have access to that. Bucket keys are a bit different, where there's a per-bucket key which has a similar scheme and then per-object keys are derived from it as needed. Together with random nonces/IVs, it ends up being a bit of a mini multi-party scheme.