I just got a nagging suspicion that AWS KMS is a fraud and provides no security above that provided by IAM permissioning.
Given society is decided have everyone commit fraud at all levels, why wouldn't all the cloud vendors do the same if they could?
(I am excluding the case where you keep all your keys on premise, which I assume no one does)