6 ms·
AWS Key Management Service
- neals 12y agoLots of new Amazon services today?
- cthalupa 12y agoThis week is the AWS re:Invent conference, lots of announcements are made during it. These were announced at the keynote today, and there's another keynote tomorrow.
- martey 12y agoThere is currently an AWS conference going on: https://reinvent.awsevents.com/ https://reinvent.awsevents.com/
- kaivi 12y agoA re:Invent banner was all over AWS sites for half a year now, I can't believe that this is it. I was expecting Jeff standing up in a suit and talking to a live audience. Instead, there is what appears to be a pre-recorded video stream of advertisements on how AWS is great: >Think you're a good architect? These 12 tips will help you get around our global, fast and secure AWS infrastructure.
- jeffbarr 12y agoAndy Jassy delivered the keynote earlier this morning to a capacity crowd. We made 5 big announcements today and have more in store for tomorrow.
- kaivi 12y agoThanks, just figured out how huge this event actually is. Any chance that VPC will support broadcast? The FAQ page is quite dry on details.
- iancarroll 12y agoThis is actually a really cool feature - the CloudHSM offering is both (very) expensive and not user friendly. This should help with big clients requiring HSMs or the like. So many cool services could be built with this if there's an open API. Edit: Sadly, it seems there's no out of the box ELB support... Would be great for TLS termination.
- bgentry 12y agoFor ELB TLS termination, AWS already stores your TLS key securely in IAM, probably using some of the same underlying technologies. What sort of integration do you want between KMS and ELB?
- iancarroll 12y agoSecurely doesn't equate to what a HSM provides. I'd be doubtful if they are (using them) right now... If IAM gets compromised, an attacker can take the key and run, opposed to them only being able to use it while they have access to the HSM. Not saying it's likely to happen.
- toyg 12y agoI put on my robe and tinfoil hat... Managing all my keys on such a service would mean trusting Amazon will not hand them over to NSA and friends (with our without NSL or sealed indictment). Which I'm rather sceptical about, tbh, considering Amazon makes quite a lot of business with governments of all sorts. EDIT: to clarify, my comment was about keys that would otherwise not sit on, or be used by, AWS images. If you make the effort to use such a tool, it makes sense to store all your keys, not just stuff that would have ended up on AWS anyway; and that's where the risk lies.
- spdy 12y agoIf you are invested on AWS does it really matter? They own the metal your software runs on and they can look at it regardless if you give them the key or not.
- toomuchtodo 12y agoDevOps here! If they can capture the memory contents of your VM, you've already lost. Get some gear, and colo it in a non-US country if you're paranoid about the NSA.
- general_failure 12y agoAnd don't use US hardware.. Best of luck with that.
- mentat 12y agoThere's GovCloud but not "non-GovCloud".
- toomuchtodo 12y agoSupermicro builds its gear in Taiwan still, no? Has been a while since I had to buy physical hardware.
- 12y ago
- lewaldman 12y agoCould any one point me what's wrong with nominal users and keys managed by system automation (AKA Puppet/Chef/SaltStack)?
- ermintrude 12y agoPCI compliance.
- EGreg 12y agoUsually when I read "security" and "centralized" in the same sentence, I think of an unsustainable model that will be disrupted in a few years.
- deleted 12y ago[deleted]