4 ms·
What I'm interested in is how should I encrypt and store sensitive user data on a server such that it is retrievable but secure.
by teapot01 11y ago
What I'm interested in is how should I encrypt and store sensitive user data on a server such that it is retrievable but secure.
- sumodirjo 11y agoDo you plan to fully encrypt data as doing full harddisk encryption?
- bigiain 11y agoWhich doesn't help one bit when some script kiddie xss-es their way into your admin backend or SQLis your entire DB out through your un-updated ad server or contact form plugin... It does help if a thief walks out with your server, or if some extremely uneducated and unprofessional law enforcement power down your server as they serve their warrant on your datacenter - but neither of those scenarios are anywhere near the top of the "reasons your sensitive data got compromised and showed up on pastebin" lists.
- DanBC 11y agoSecure from what? Secure from remote but unskilled attackers using auto tools poorly? Secure from remote but skilled users targetting your system? Local and skilled users targetting your system? Law enforcement smashing the door down? Well formed legal documents? Well funded government agencies? Malicious employees?
- teapot01 11y agoUltimately I think the main danger is a skilled attacker targeting the system. That said I would like to secure data from a local attacker as well. Ultimately I understand that it will be difficult to secure fully against someone with hardware access but any risk mitigation practices I could use?