|
|
|
|
|
by sl1ck731
2164 days ago
|
|
I've been thinking about this in regard to AWS. The encryption at rest for most things is completely transparent so the only thing your really protected against is someone walking into a data center and grabbing your drive somehow. Or improperly disposed drives. Maybe some kind of hypervisor or SAN exploit but I don't know much about that. AWS seems to have turned part of the cloud operating model they are supposed to be responsible for back onto the user and no one questions it. |
|
You can also set up workflows such as your client owning the encryption key that encrypts data held by you and they can revoke it at any time. Slack has a similar system and I was asked by a large financial institution about the same. I expect to see this more in future.