Re: [Proposal] Table-level Transparent Data Encryption (TDE) and KeyManagement Service (KMS) - Mailing list pgsql-hackers

From Chris Howard
Subject Re: [Proposal] Table-level Transparent Data Encryption (TDE) and KeyManagement Service (KMS)
Date
Msg-id 7c7f5242-05c8-ebd8-5e19-4a1f84f98e65@elfpen.com
Whole thread Raw
In response to Re: [Proposal] Table-level Transparent Data Encryption (TDE) andKey Management Service (KMS)  (Laurenz Albe <laurenz.albe@cybertec.at>)
List pgsql-hackers
Or on your laptop



On 3/4/19 11:55 AM, Laurenz Albe wrote:
> Masahiko Sawada wrote:
>> Why do people want to just encrypt everything? For satisfying some
>> security compliance?
> I'd say that TDE primarily protects you from masked ninjas that
> break into your server room and rip out the disks with your database
> on them.
>
> Or from people stealing your file system backups that you leave
> lying around in public.
>
> My guess is that this requirement almost always comes from security
> departments that don't know a lot about the typical security threats
> that databases face, or (worse) from lawmakers.
>
> And these are probably the people who will insist that *everything*
> is encrypted, even your commit log (unencrypted log? everyone can
> read the commits?).
>
> Yours,
> Laurenz Albe
>
>
>
>



pgsql-hackers by date:

Previous
From: Laurenz Albe
Date:
Subject: Re: [Proposal] Table-level Transparent Data Encryption (TDE) andKey Management Service (KMS)
Next
From: Tom Lane
Date:
Subject: Re: POC: converting Lists into arrays