Is Encryption at Rest a Scam?
evervault.com
evervault.com
No, it’s not a scam. Should you use it for your data? Yes. Does it prevent you being h4x0red? No. Defense in the depth.
> Nothing in this diatribe argues that encryption at rest is creating a net negative, outside of it being represented as a be-all and end-all security measure. When I say encryption at rest is a scam, I’m talking about it from the eyes of the purchaser. And given that it’s their data at risk, this is the standpoint that matters.
> developers often rely on encryption at rest as a gold standard security measure
and they shouldn't.
Security isn't a list of checkboxes to tick.
Significantly: there are a whole host of risks that is doesn't mitigate, that it is not intended at all to mitigate, that people who don't know any better might assume are dealt with when things are pushed as secure “because the data is encrypted at rest”. If you read TFA you'll see that it details some of these concerns.
https://en.wikipedia.org/wiki/Betteridge%27s_law_of_headline...
We should however distinguish between encryption at rest for storage devices and other forms of encryption at rest.
You can also encrypt data at rest at the application or database layers too, and they provide protection against more than just physical access to the storage device.
Like all encryption, it's all about who can get the keys.
"Encryption at rest protects companies against the least common—and trickiest—attack vector: physical theft of hard drives" is a pretty odd view to see it if you're into security, as these guys are.
Which is, hilariously, send us your data and we'll encrypt it for you! Very secure, much privacy.