6 ms·
But that is exactly the point. You want to ensure that disks later sold by your cloud provider do not contain your data in plain. That's the whole point with en
by exitheone 5y ago
But that is exactly the point. You want to ensure that disks later sold by your cloud provider do not contain your data in plain. That's the whole point with encryption at rest. It's not supposed to protect you against an attacker with root access to your server.
- itisit 5y agoThe big cloud providers destroy old drives.
- deleted 5y ago[deleted]
- jeffbee 5y agoBut encryption at rest does protect you from insider or attacker access with full privileges on the servers where the data is stored. The data would necessarily be visible to a root user on the system where the data is being decrypted by an application, but that's not necessarily the same node.
- deleted 5y ago[deleted]
- yashap 5y agoA good, fairly recent example from the city I live in, of hard drives being sold that were (accidentally) absolutely chock full of unencrypted customer PII: https://www.google.com/amp/s/globalnews.ca/news/4476625/ncix-server-data-breach/amp/ https://www.google.com/amp/s/globalnews.ca/news/4476625/ncix...