3 ms·
Related snake oils: - Customer-Managed Encryption Keys -- US cloud providers love to market this - Confidential Commuting -- where the root of trust is either
by anticristi 3y ago
Related snake oils:
- Customer-Managed Encryption Keys -- US cloud providers love to market this
- Confidential Commuting -- where the root of trust is either the same company (AWS) or a US processor manufacturer (Azure, Google).
- MattPalmer1086 3y agoI think customer managed keys are often misunderstood. They aren't innately more secure than cloud provider managed keys from the cloud provider. They just give the customer the ability to manage the key lifecycle. Key generation, rotation, revocation. This is still a useful capability.
- anticristi 3y agoIndeed. I'm unsure whether this misunderstanding is "nurtured" or is simply "wishful thinking". Unfortunately, I heard too often CMEK being seen as "the holy grail" of processing data safely on untrusted cloud providers.
- MattPalmer1086 3y agoYes, I encounter that attitude too quite frequently. If you need to manage the keys in to particular schedules or policies, it's obviously what you want. That might be more secure in some ways than leaving it to the cloud provider, depending on what you actually do with the capability. But many people just stop at CMEK Is More Secure...