Re: [Proposal] Table-level Transparent Data Encryption (TDE) andKey Management Service (KMS)
От | Laurenz Albe |
---|---|
Тема | Re: [Proposal] Table-level Transparent Data Encryption (TDE) andKey Management Service (KMS) |
Дата | |
Msg-id | 0ae7bc508f61c916d7c0448be571ede34411d4d0.camel@cybertec.at обсуждение исходный текст |
Ответ на | Re: [Proposal] Table-level Transparent Data Encryption (TDE) and KeyManagement Service (KMS) (Masahiko Sawada <sawada.mshk@gmail.com>) |
Ответы |
Re: [Proposal] Table-level Transparent Data Encryption (TDE) and KeyManagement Service (KMS)
Re: [Proposal] Table-level Transparent Data Encryption (TDE) and KeyManagement Service (KMS) |
Список | pgsql-hackers |
Masahiko Sawada wrote: > Why do people want to just encrypt everything? For satisfying some > security compliance? I'd say that TDE primarily protects you from masked ninjas that break into your server room and rip out the disks with your database on them. Or from people stealing your file system backups that you leave lying around in public. My guess is that this requirement almost always comes from security departments that don't know a lot about the typical security threats that databases face, or (worse) from lawmakers. And these are probably the people who will insist that *everything* is encrypted, even your commit log (unencrypted log? everyone can read the commits?). Yours, Laurenz Albe
В списке pgsql-hackers по дате отправления: