https://aws.amazon.com/blogs/aws/amazon-s3-encrypts-new-obje...
https://aws.amazon.com/blogs/aws/amazon-s3-encrypts-new-obje...
I checked that link and they call it "server-side encryption" -- do they mean encryption at rest? If so, it seems terrible that they would allow data to live unencrypted on their non-volatile storage, why do they even give the customer that option?
Other than for very specific kinds of customers that want to supply their own encryption keys, why should it even be their concern? The whole point of cloud is to take the hardware away. Encryption is cheap, just do it.
I take special offense to teams who store Terraform state in S3 and claim "it's encrypted" when it is so easy for other users in the same AWS account can easily access the buckets contents.
GCS is slightly more secure but you really need client side encryption to be safest.
My advice: check and make sure your bucket policy you use for the state has an explicit deny (resource *, principal *) and then you explicitly allow only the user / role that requires access to the TF state.
Things to watch out for are providers that store sensitive info in your state. For example, if you use Vault and you read a secret out of Vault with Terraform then the secret will be saved in your Terraform state which, painting with broad strokes, largely invalidates the purpose of Vault. Lots of providers do this, some are getting better about not requiring sensitive info to be saved in the state or included in the config.