Amazon S3 now automatically encrypts all new objects
aws.amazon.com
aws.amazon.com
This is an incredible piece of engineering. Almost as impressive as when they made S3 read-after-write consistent a couple of years ago: https://aws.amazon.com/blogs/aws/amazon-s3-update-strong-rea...
The read-after-write consistency was definitely an impressive change. This however, not so much.
- [x] Microsoft Azure (https://learn.microsoft.com/en-us/azure/storage/common/stora...)
- [x] Google Cloud Storage (https://cloud.google.com/storage/docs/encryption)
- [x] Backblaze B2 (https://help.backblaze.com/hc/en-us/articles/217973398-Encry...)
- [x] Wasabi (https://wasabi-support.zendesk.com/hc/en-us/articles/1150016...)
- [ ] DigitalOcean (https://www.digitalocean.com/community/tutorials/how-to-crea...)
- [ ] DreamHost (https://help.dreamhost.com/hc/en-us/articles/360001089163-En...)
- [ ] Linode (https://www.linode.com/docs/guides/server-side-encryption/)
I don't see it as just a checklist thing: if Amazon ever gets hacked, you wouldn't want your data compromised as a result. Of course, if they manage to steal the keys too, it would still be.
I assume the read credentials must ipso facto decrypt the object. So encryption at rest protects you against an inside job at AWS (smash and grab drives) or government confiscation. Am I thinking about this correctly?
I’m told the AWS data centers has red zones, which no harddrive can be taken out of, without being mechanically and violently destroyed first.
S3 is frankly amazing technology; probably the most robust and well rounded piece of cloud tech that exists.
On the AWS scale, object storage servers will probably be filling entire datacenters (or at least an appreciable portion of each datacenter), so it's very easy to see them being well into the exabyte (= million terabyte) scale, though probably not zettabyte (= billion terabyte) yet.
[1] Source: I help maintain an object storage for a private cloud. Disclaimer: These are not the exact numbers for our nodes, but in the same ballpark.
To allow this to double as ”user level” encryption you need to coordinate & manage the keys used vs. just picking something random when the drive is formatted. This is how Apple’s and others’ full-disk encryption has worked for years.
> Amazon S3 now automatically applies S3 managed server-side encryption (SSE-S3) as a base level of encryption to all new objects added to S3