> If Amazon faced a subpoena that required it to keep the order secret, such encryption would be useful to customers. “If the data is encrypted, all we’d be handing over would be the cypher text,” he said.
> If Amazon faced a subpoena that required it to keep the order secret, such encryption would be useful to customers. “If the data is encrypted, all we’d be handing over would be the cypher text,” he said.
It does protect you for S3 if and only if you conduct the crypto outside AWS and generate/manage the keys yourself (e.g. how tarsnap does it). It may protect you for some of the other AWS services IFF you use them in the same hybrid way, but I don't know of anyone who uses AWS's database services without just using EC2 nodes primarily to talk to them.
It's missing a few elements you'd need to build a really awesome secure cloud, though. (actually, intel hardware was missing it)
http://www.blackhat.com/presentations/bh-dc-09/Wojtczuk_Rutk...