← Back to context

Comment by tgsovlerkhgsel

19 hours ago

They're likely going to target two datacenters, not the datacenters + your medium sized company's office NAS and the safe in the office manager's home.

(Encryption handles confidentiality concerns.)

> (Encryption handles confidentiality concerns.)

Which is why data residency is such a stupid concept.

  • Yes and no. For example if you are doing Azure, technically Azure can see tenant traffic I believe and you need to use both a Platform Key and CMK for data rest. VMs need encryption at host turned on too.

    There is nothing to say that a determined adversary may still get at your data so it needs to stay in country.

    • Yeah same with AWS - they say they can't see my custom KMS key but... this stuff all lives on their servers, not on my servers. AWS definitely have the ability to see my KMS keys and decrypt my data but I assume that they won't unless a judge tells them to.

      1 reply →