Live data from Hacker News

Is Encryption at Rest a Scam?

evervault.com

1–10 of 15 posts

Re: Is Encryption at Rest a Scam?

#3
post #2

Sheesh, clickbaity title. No, it’s not a scam. Should you use it for your data? Yes. Does it prevent you being h4x0red? No. Defense in the depth.

From the article:

> Nothing in this diatribe argues that encryption at rest is creating a net negative, outside of it being represented as a be-all and end-all security measure. When I say encryption at rest is a scam, I’m talking about it from the eyes of the purchaser. And given that it’s their data at risk, this is the standpoint that matters.

Re: Is Encryption at Rest a Scam?

#4
post #2

Sheesh, clickbaity title. No, it’s not a scam. Should you use it for your data? Yes. Does it prevent you being h4x0red? No. Defense in the depth.

Most corporate blogs are less than useless. Clickbait titles are getting more and more prevalent too. "We're not sustainable" from yesterday is another example.

Re: Is Encryption at Rest a Scam?

#5
I think "scam" is a bit strong. It maybe offers less value in some scenarios that people assume, so perhaps offers a false sense of security. People have been saying for many years that ticking the "encrypt at rest" box in your cloud console only protects against things like people breaking in to their data centre, and they are right. On the other hand, it's easy to do, and while arguably not helping much with actual security, it can be a cheap way of meeting policy requirements.

Re: Is Encryption at Rest a Scam?

#6
post #3
post #2

Sheesh, clickbaity title. No, it’s not a scam. Should you use it for your data? Yes. Does it prevent you being h4x0red? No. Defense in the depth.

From the article: > Nothing in this diatribe argues that encryption at rest is creating a net negative, outside of it being represented as a be-all and end-all security measure. When I say encryption at rest is a scam, I’m talking about it from the eyes of the purchaser. And given that it’s their data at risk, this is the standpoint that matters.

Exactly. As explained in the article itself, the title is pure clickbait.

Re: Is Encryption at Rest a Scam?

#7
post #3
post #2

Sheesh, clickbaity title. No, it’s not a scam. Should you use it for your data? Yes. Does it prevent you being h4x0red? No. Defense in the depth.

From the article: > Nothing in this diatribe argues that encryption at rest is creating a net negative, outside of it being represented as a be-all and end-all security measure. When I say encryption at rest is a scam, I’m talking about it from the eyes of the purchaser. And given that it’s their data at risk, this is the standpoint that matters.

"not creating a net negative". Blog author doesn't want to commit to anything. What's the point if they're not going to make a point?

Re: Is Encryption at Rest a Scam?

#8
post #2

Sheesh, clickbaity title. No, it’s not a scam. Should you use it for your data? Yes. Does it prevent you being h4x0red? No. Defense in the depth.

Yes, a title with a question mark can usually be answered by a simple "no". If it was a yes, the title "Encryption at Rest is a scam" would be more likely.

https://en.wikipedia.org/wiki/Betteridge%27s_law_of_headline...

Re: Is Encryption at Rest a Scam?

#9
Minimizing the time the data stored as plaintext in memory is still a good idea. Minimizing the time the key stored in memory is still a good idea. Minimizing the the code have access to the key is still a good idea.

Re: Is Encryption at Rest a Scam?

#10
I can imagine a couple of scenarios where no physical access to the drive is required for it to be useful. It's not like you're always on the machine which has the key in memory or on storage, but the sensitive data could be accessed anyway, for example through a share.

"Encryption at rest protects companies against the least common—and trickiest—attack vector: physical theft of hard drives" is a pretty odd view to see it if you're into security, as these guys are.

Post reply on HN