Author here. Agree, I cover these in the article. Crypto-shredding might be the AWS' motivation to enable the feature as a 0-click default. But for the customers, they don't get much beyond the compliance checkbox, and that too is questionable as more and more auditors become aware of cloud security controls.
Author here. Technically, they can. HOWEVER if this threat is part of a customer's risk profile, i.e., they cannot risk even a possibility of AWS having access to their data, then use client side encryption.
AWS will now encrypt all new data in its Amazon S3 storage service by default. Huge announcement, secure default for the win, sure, but it gives a false sense of security.
Unfortunately I can’t. If you want to try out, it’s a doc generated through Google doc’s built-in templates (which perhaps is the reason for bloated size).