Earlier quoted context omitted.
From the article: > Nothing in this diatribe argues that encryption at rest is creating a net negative, outside of it being represented as a be-all and end-all security measure. When I say encryption at rest is a scam, I’m talking about it from the eyes of the purchaser. And given that it’s their data at risk, this is the standpoint that matters.
"not creating a net negative". Blog author doesn't want to commit to anything. What's the point if they're not going to make a point?
> developers often rely on encryption at rest as a gold standard security measure
and they shouldn't.
Security isn't a list of checkboxes to tick.