Are there any publicly available case reports of where an encrypted database protected data?
Are there any publicly available case reports of where an encrypted database protected data?
I've personally run across "dump.sql" files before in public s3 buckets, and as I understand it, this would help in that case.
That kind of sounds like something half of the companies I worked for would end up eventually doing, fair point.
For example, since our sensitive DB fields are encrypted, relevant developers can get full read only access to the DB for debugging/analysis purposes without needing to worry about leaked PII. Similarly, we can log all of our DB queries, including fields, because the sensitive fields are encrypted.
This has huge operational benefits, and for compliance reasons is usually the best way to solve this problem. You can do things like limit access to columns by DB roles, but that is much more fraught, and it doesn't give you the logging benefits.