3 ms·
Not encrypting user data and then being hacked resulting in compromised user DNA details certainly isn't a positive for PR. Can someone tell me why more compani
by toader 3y ago
Not encrypting user data and then being hacked resulting in compromised user DNA details certainly isn't a positive for PR. Can someone tell me why more companies don't encrypt data at rest and if that would have prevented the leak?
- bombcar 3y agoBecause actually encrypting at rest usually offers a ton of hassle for little actual additional security. For example, if done right, you need to decrypt with some form of passcode/system on boot, etc, etc. But once "unlocked" the system has access to the data, and usually the hackers come in via the "live" system. Things like backups are usually encrypted but not always, but the number of incidents of people stealing physical media is pretty low compared to ransomware/remote hacks.
- GartzenDeHaes 3y agoEncrypting data at rest in a data center doesn't provide as much protection as you might think. The level of system access in order to access the raw data files is usually about the same as accessing the higher level database system itself. So at best you're adding a couple of extra steps to the attack. Since there are usually significant costs to encrypting production databases, such as CPU utilization, many organizations choose to focus on other security controls. Data encryption is just one of many security controls at play in a scenario such as this and the security team has to carefully pick their battles to avoid just being completely ignored as the "say no to everything" guys.
- jibe 3y agoThe hack was logging in with reused user credentials, then scraping the ancestry data. Encryption would not have helped in this case.