3 ms·
The various internal encryption statements seem to be speaking to the various NSA issues.
by corresation 13y ago
The various internal encryption statements seem to be speaking to the various NSA issues.
- omh 13y agoDoes anyone who is concerned about the NSA issues seriously think that encryption (in the way it's implemented here) would be any help?
- pg_is_a_butt 13y agothe data is often transferred between google datacenters, as the DB is "transient"... that transfer is probably also encrypted, but the NSA may already have those links compromised... encrypting the data and the transport can't hurt...
- michaelt 13y agoThe encryption that has been proposed does nothing to address the NSA issues. Amazon has a similar feature on S3 - they will encrypt your data on upload, and automatically decrypt it when you read it [1]. From a security perspective, this appears to be useless [2]. I suppose it might be useful if you're at an organisation with a rule saying "all data must be encrypted at rest" where the rule cannot be changed, but does not have to be implemented in an effective or useful manner. [1] http://aws.typepad.com/aws/2011/10/new-amazon-s3-server-side-encryption.html http://aws.typepad.com/aws/2011/10/new-amazon-s3-server-side... [2] http://security.stackexchange.com/questions/8765/what-does-amazons-s3-server-side-encryption-protect-against http://security.stackexchange.com/questions/8765/what-does-a...
- GauntletWizard 13y agoThere is some, albiet limited, use: a) It protects your data from hard-drive theft. Not an especially common occurrence in Amazon or Google scale datacenters b) It segments out the storage admins at your cloud-hosting provider from being accidentally granted access to your data. Useful from a principle-of-least-privilege standpoint.
- michaelt 13y agoSeems to me these claims of encryption are like selling full outfits with bulletproof socks and telling customers they're buying bulletproof clothes. It's technically true, and it does offer protection against a minute range of threats, but it's mostly dangerous snake oil that'll end up with people who think they have protection when they don't.
- corresation 13y agoI wouldn't quite say it does nothing, depending upon where in the stack the encryption is performed. If it's in the application layer (e.g. similar to transparent data encryption with SQL Server), it would stop anything else in user or system space from seeing the data short of hacking the DB process. Though it seems this isn't the case given that they're doing backup encryption separately and later. They also talk about in-network encryption, which does directly speak to the NSA issues. All of it is under the auspices of "network security", which is a growing concern because of the NSA debacle. And to answer ohm's comment, yes many people who know tangentially about the NSA accessing data don't really know that much about the practical applications of security. Something like this absolutely helps them drop a bullet point declaring security to bolster their cloud strategy.