How exactly will this protect my data?
How exactly will this protect my data?
Just think: there will be AWS accounts using this while their master AWS console account continues to have a single-dictionary-word password and no MFA. Truly the Cloud is the silver bullet to save us all from shoddy CIOs!
The only way to do this safely is to do the encryption yourself prior to uploading to S3 and manage the keys yourself.
When Dropbox's authentication layer failed, their encryption was meaningless. Same thing here: data is still vulnerable to errors, misappropriation, subpoena, etc.
You would be negligent not to implement this if you're storing sensitive data on AWS. No?
From a security point of view the encryption adds no value at all: Either I trust Amazon to not look at my data, or I don't trust them. If I don't trust them with my data, surely I also can't trust them with my encryption keys.