AWS Key Management Service
aws.amazon.com
aws.amazon.com
Managing all my keys on such a service would mean trusting Amazon will not hand them over to NSA and friends (with our without NSL or sealed indictment). Which I'm rather sceptical about, tbh, considering Amazon makes quite a lot of business with governments of all sorts.
EDIT: to clarify, my comment was about keys that would otherwise not sit on, or be used by, AWS images. If you make the effort to use such a tool, it makes sense to store all your keys, not just stuff that would have ended up on AWS anyway; and that's where the risk lies.
If the get the server with the hsm in it via a NSL, game over. That being said, it is impossible for a hack to get the private keys, so this is still a massive win.
AWS CloudHSM provides you with a dedicated hardware device installed in your Amazon Virtual Private Cloud (VPC) that provides a FIPS 140-2 Level 2 validated single-tenant HSM to store and use your keys. You have total control over your keys and the application software that uses them with CloudHSM.
AWS KMS allows you to control the encryption keys used by your applications and supported AWS services in multiple regions around the world from a single console. Centralized management of all your keys in AWS KMS lets you enforce who can use your keys, when they get rotated, and who can manage them. AWS KMS integration with AWS CloudTrail gives you the ability to audit the use of your keys to support your regulatory and compliance activities.
It's a good initiative, and as long as you trust the company, you can trust that they probably haven't signed a compromised key, or that someone's been able to extract the key from a HSM (something that's really hard, but see eg: the (first) XBOX hack involving an electron microscope for reading key-bits from ROM).
So many cool services could be built with this if there's an open API.
Edit: Sadly, it seems there's no out of the box ELB support... Would be great for TLS termination.
If IAM gets compromised, an attacker can take the key and run, opposed to them only being able to use it while they have access to the HSM. Not saying it's likely to happen.
I was expecting Jeff standing up in a suit and talking to a live audience. Instead, there is what appears to be a pre-recorded video stream of advertisements on how AWS is great:
>Think you're a good architect? These 12 tips will help you get around our global, fast and secure AWS infrastructure.
Any chance that VPC will support broadcast? The FAQ page is quite dry on details.