Hacker News new | ask | show | jobs
by attentive 1275 days ago
That's a good sentiment. But you can say the same for the aws encryption.

I.e. how do you even know it's working and your data is encrypted? Just because API says so, doesn't mean it's so. There is no way for you to verify. Is there? Unless you encrypt on your end, you can't be sure.

1 comments

Many reasons:

I know people who work there. I've read the infrastructure designs. I know Amazon audits themselves. I know AWS has third party audits. I know AWS has government and enterprise users who require their partners be legally liable for improper implementation. I do not subscribe to conspiracy.

The same is true for other points one through six, if you choose to trust aws. But somehow "It's incredibly naïve to not use encryption at rest on AWS".