Hacker News new | ask | show | jobs
by ajdecon 4797 days ago
Probably still not acceptable for many of these situations, especially when you're signing these kinds of data custody agreements. Oftentimes they specify requirements for physical custody of the hardware, and even if they don't, adding third parties into the mix (Amazon and you) may make the auditing requirements more complicated.

A lot of the time, these requirements are more about auditing and liability than about technical security measures.