Shorts · Mar 28, 2019
Why and How to Keep Your Decryption Keys Off Web Servers
0Sign in to vote or save
This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
Suppose a worst-case scenario happens: an attacker finds a remote code execution vulnerability and creates a reverse shell on one of your web servers. They then find the database credentials, connect to your database, and steal the data. For unencrypted data and data encrypted at the storage level, it’s game over. The attacker has it all. If data is encrypted at the application level with…
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.