logoalt Hacker News

firesteelraintoday at 12:54 AM1 replyview on HN

Yes and no. For example if you are doing Azure, technically Azure can see tenant traffic I believe and you need to use both a Platform Key and CMK for data rest. VMs need encryption at host turned on too.

There is nothing to say that a determined adversary may still get at your data so it needs to stay in country.


Replies

jamesfinlaysontoday at 1:40 AM

Yeah same with AWS - they say they can't see my custom KMS key but... this stuff all lives on their servers, not on my servers. AWS definitely have the ability to see my KMS keys and decrypt my data but I assume that they won't unless a judge tells them to.

show 1 reply