S3's "encryption at rest" is transparent (see: http://docs.aws.amazon.com/AmazonS3/latest/dev/serv-side-enc...). If someone (or some server) has access to the S3 bucket, they have access to all of the data. Control then is delegated to IAM roles and permissions, not to the crypto model.
> As long as you authenticate your request and you have access permissions, there is no difference in the way you access encrypted or unencrypted objects.
The only advantage of S3 encryption is that if someone walks out of the data center with a disk, they can't read the data on it.