'Encryption-at-Rest' Is Crap

preview_player
Показать описание
Encryption at rest is a phrase that is too often advertised as data protection. In most scenarios, it's probably not. The bottom line is this: encryption at rest doesn't tell you if the data is protected. #encryptionmyths #datasecurity
Рекомендации по теме
Комментарии
Автор

Your video content is better than its thumbnail. I took a chance and clicked on it and it paid off for me.

dsulvadarius
Автор

Encryption with separate KMS like Vault or AWS KMS is the best way if these plugins are available in the DB engines

arunabraham
Автор

Hi, safeguards for data at rest is just for the hardware where the data are, but what safeguards we need to protect the data in the hardware ? Thanks !

杜佳子
Автор

I think you are mixing encryption at-rest with filesystem encryption. The one that you are decribing is filesystem encryption that is only good for offline attacks (if someone stole your laptop) but encryption at-rest means the application encrypt the data before writing it to the disk and decrypt it when reading it from the disk. At-rest encryption is good against both online and offline attacks.

alivarfan
Автор

The good old security circus continues.

leccine