This post discusses the importance of encryption at rest in web and cloud applications and the need for a clear threat model. It explores the concept of security theater and the risks it aims to mitigate. The post also explains client-side encryption and the need for proper key management and encryption algorithms. It highlights the issue of confused deputies and offers solutions to mitigate the risk. The post concludes by urging developers to improve their understanding of encryption at rest and engage in threat modeling.

12m read timeFrom scottarc.blog
Post cover image
Table of contents
Why should we listen to you about this topic?Why and How to use Encryption At Rest to Protect Sensitive DataSecurity Considerations for Client-Side EncryptionWhy aren’t things better already?Closing Thoughts
1 Comment

Sort: