Cloud Encryption Options

7:23 · Watch on YouTube ↗

Transcript 1,145 words · about 8 min to read

Auto-generated captions from YouTube, not hand-corrected, so names and technical terms may be imperfect. The video is authoritative.

hey how's it going Steve clauser from the CTO visor toss and we're doing a CTO dose and take a look we roasted the nor can wanna dip the nor Easter I think they named it yeah lost track except for this so we survived the storm we just at least I get a made it here to New York soon yep red tech employees put on by Arjun and Max they do a great job I'm soft great event so we're taking a break from the presentation is to

talk a little a WX security I'm sure can introduce yourself to the CTO of ISIL sure my name is Kenneth Hawaii I am a technical marketing engineer at a company called rubric and we just really focus around helping customers so speaking of cloud theater management you did a recent it's like ebook man's 5,000 word yes find a blog folks is like a research paper almost a little bit yeah yeah so yeah so I tend to training a Quelaag content it's one of my job to socialize

enjoyed are I tend to pick topics that a scratch an itch that I have all the stuff they're doing today if today's about data breaches seems like every single day there's a another s3 bucket to the world I just felt like David questions a lot of those topics that people want it to and probably they didn't watch it they need to know more about so I just kind of died in and said let's let me start writing a blog posts about how the different public clouds

do data encryption and it kind of grew from that one blog post into a what will be a five-part series so from a high levels help me out with an approach to data encryption when I think about data encryption in cloud I'm thinking you know what I encrypt I take my data warm premises where I encrypt my data within the application within my environment then I put it into a bucket right obviously there's judging by your blog for the cloud providers give us native options for

doing encryption yeah tons of extra so so one approaches in crack to encrypt your data first mm-hmm upload it but the three public of and this also give me the after saying I'm gonna send it I'm gonna upload the data first and then have the cloud provider provide the encryption service in this pros and con Siddhant right obviously you do it on-site Joe is possible managing all that so llama was writing about was the colinear all those different options and I think at the encryption code

is actually that in some ways the release interesting or disappointing right most important part is something called key management yeah that's the the the have a basic unencrypted decrypting do you have a lot of times people worry about old cow provider has my encryption key so they have both they decrypted data in the keys so if a bad guy or the government maybe those are the same people what get to the data the cloud provider have both the key in the encrypted data right and I

have no control that's right so so one option there like customers just access to the challenge there is if you lose the keys basically there's no way to decrypt right then it's done there's a lot of garbage rights right so it is there's a trade-off that you have to kind of guy or do I want do you want to take do I wanna take on responsibility imagine the smoke slide the provider doesn't happen all do I want to say what my job isn't to worry about

any of that my job is to create stuff with a business I'm just gonna let the club about anything I'm gonna trust that they're not gonna use those keys so I did a thing on AWS key Christian man is a UW certify to three different levels and three different types of key management is that consistent across to cloud providers as well so AWS clue definitely is the most mature mm-hmm feature set which makes sense they've they've been around the longest at Azure and Google clouds catching

up but they don't they definitely do not the same number of options so there's just a lot of reasons I end up doing one the part for that blog series is the longest one so when you do to pretzels are 20,000 a roughly 20,000 word oh sorry 5,000 words roughly 20 pages in the art of PDF which is why I actually actually printed Al's of Pediatrics but it's so people download it so not to scroll through actually might even be $20,000 that one well actually literally

walked exactly how encryption was for Evie all three cloud providers is enlisting option because they are so different and so it well I'm trying to get across to people is you should evaluate how each of them was done in secret maps to a how your application works and be what your company's policy so one example is Google Cloud has default encryption mm-hmm that they do when the later when the data lands but they don't actually give any tools to what you do encryption on premises oh

you had us do law that yourself so until it gets into their actual infrastructure the data is encrypted yeah you think it's equipment in transit right a bit but what that means is there's gonna be a moment some amount of time be very short where it gets decrypt it once it gets to Google and then they have to encrypt your vision to land it and in theory if you're if your path you want to be paranoid or care for that you could attack potential set to

that data during that span time so where can people find this many novel yeah yeah so it's all my pastas personal blog sites are you go to architect musings calm and just do a search on encryption for currently for and then eventually five blog posts are and you your Twitter's well I can be flying on Twitter yeah I'm at kenzley and Weiss's ke n hu i and y and generally i treat about anything related to cloud to security and sometimes food alright and that's it for

this CTO dose you can find me on the web CTO dose calm for these videos and at CTU advisor for my twitter handle and you can find the podcast subscribe to us both the CT those two podcasts you can get this on podcast and maybe you're listening to it on the podcast sitio de sitio the CTO advisor calm talking next CTO dose