There's a few different revocation options:
* `grant-computer` creates a KMS grant as per http://docs.aws.amazon.com/kms/latest/developerguide/grants.... . `revoke-computer` removes the grant without touching the keys.
* The AWS access keys for the IAM user the tool uses, which can be rotated, revoked, recreated, etc...
* The per-disk encryption key, which can be deleted from DynamoDB
* The KMS CMK, which can be deleted, disabled, etc...
I mainly wanted to solve having to plug in a keyboard and type something in, or having a key on a USB stick and be diligent enough to take it out of the home.