What narrow attack is AWS transparent KMS (en/de)cryption protecting against if AWS holds the keys? So far all I can think of is
- someone unplugging a drive at AWS data center & walking away with it
- um, nothing
Look, if RDS is encrypted, but an attacker stole the connection string, bye-bye data.
If a dev posts a root IAM key to public github, bye-bye data
If an encrypted s3 bucket has public permissions because the UI is one big pit of failure, bye-bye data.♡ 0 ↻ 0If your ec2 instances volume is encrypted but your PHP app lets script kiddies read everything below / then, bye-bye data.
This is like security-by-locking-just-the-pet-door & leaving the front & backdoor unlocked.
Point me to something more intelligible than AWS's KMS docs♡ 0 ↻ 0because I sort of hope that I'm wrong and that there is some clever mechanism that does make KMS a bizarre ritual. (And as far as fearing your hoster goes, if the CIA, GRU or MSS asks for data, I assume AWS transparently decrypts it- they have the keys)
♡ 0 ↻ 0* doesn't* make KMS a bizarre ritual. Shoot no way to edit a tweet storm.
♡ 0 ↻ 0