4 ms·
It's a whole lot easier to store the keys in a special hardened location than it is to store your whole storage.
by rkangel 6mo ago
It's a whole lot easier to store the keys in a special hardened location than it is to store your whole storage.
- ozlikethewizard 6mo agoRight but access to those keys will be available in an unhardened location then? Otherwise you're serving encrypted data. So if the system accessing the data and using the keys is compromised, which we can assume is the case if the data is compromised, then access to the keys is as well? Maybe I'm being an idiot but it seems like a lot of extra complexity to protect against really only physical attacks where someone directly steals the data storage.
- winstonwinston 6mo ago> to protect against really only physical attacks where someone directly steals the data storage. Yes, physical access poses a significant risk to data security, it should not be ignored.
- ozlikethewizard 6mo agoAren't we legislating the wrong problem here then though? I'd argue prioritising the physical security of your drives over encrypting them is a better aim for services. As if someone can physically steal your drives they've still DOSed your system even if they cannot accesd the content.