Hacker News new | ask | show | jobs
by stop50 37 days ago
You are missunderstanding the transport encryption(everything related to authentication and pg_hba.conf) and the encrytion of the data at rest.

You want the encryption at rest. For that you have 3 Options:

1. Encryption in the application.

2. Use of pgcrypto as documented.

3. Encryption of the partition where postgres stores the data via LUKS or similar.

For 1. and 2. it means that indices for encrypted columns become useless and are only a waste of cpu time.

2. has the problem of transitting the key at the start of the connection, so it needs to be encrypted(tls encryption).

Its a bit of an fault with the documentation since it mixes the two types of encryption up.

1 comments

Thank you for response.

>You are missunderstanding the transport encryption(everything related to authentication and pg_hba.conf) and the encrytion of the data at rest

Correct! My questions perhaps implied one is connected to the other whereas they are completely separate. I could have been clearer.

>it means that indices for encrypted columns become useless and are only a waste of cpu time.

are you saying that blunt-force encryption of all data-at-rest renders indexes pointless? Could you provide more context here?

Cheers

When an column is encrypted you can't index the cleartext since it undermine the encryption and if you encrypt it in the application then postgres never had the cleartext. Pgcrypto encrypts at an higher level than the indexer operates, so it sees only the encrypted data.