It's possible that you've protected the data at rest, but if some 'get' operation is just going to serve it up, what is the effective difference?
It's possible that you've protected the data at rest, but if some 'get' operation is just going to serve it up, what is the effective difference?
An attacker is forced to either exfiltrate the data slowly (so the surge isn't noticed) or alert ops monitoring that the decryption service is unusually active.
Defense in depth raises the difficulty in going unnoticed and raises the time it takes to succeed.
Edit: the key comes from the user, its not stored anywhere on a server. The key can optionally never leave the user's device.
Does it mean if user loses his key - he wont be able to get access to his data?
This presupposes you know what you're doing, security-wise, on your network, and with your backups, and with temporary data on servers. All of your interior traffic is encrypted, right? Right.
It doesn't sound like Equifax was even on the map.