Hacker News new | past | comments | ask | show | jobs | submit login

> It's incredibly naïve to not use encryption at rest on AWS with how incredibly easy and problem free it is to deploy.

It shocks me that this isn't on-by-default in AWS like it is on GCP.




Backwards compatibility — GCP started enough later that their hardware could do this at close to zero cost but by then AWS had many large customers who had made decisions based on the performance delta.

By now that's moot so I'd assume they'll set it by default for new accounts at some point but there's a regional option which you can turn on by default:

https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncry...

If you use tools like Security Hub with the Amazon Foundational Security Best Practices suite of controls enabled there's a specific check for that setting:

https://docs.aws.amazon.com/securityhub/latest/userguide/sec...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: