TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

AWS Key Management Service

109 pointsby leefover 10 years ago

5 comments

toygover 10 years ago
I put on my robe and tinfoil hat...<p>Managing all my keys on such a service would mean trusting Amazon will not hand them over to NSA and friends (with our without NSL or sealed indictment). Which I&#x27;m rather sceptical about, tbh, considering Amazon makes quite a lot of business with governments of all sorts.<p>EDIT: to clarify, my comment was about keys that would otherwise not sit on, or be used by, AWS images. If you make the effort to use such a tool, it makes sense to store all your keys, not just stuff that would have ended up on AWS anyway; and that&#x27;s where the risk lies.
评论 #8598201 未加载
评论 #8598242 未加载
评论 #8598784 未加载
评论 #8599560 未加载
iancarrollover 10 years ago
This is actually a really cool feature - the CloudHSM offering is both (very) expensive and not user friendly. This should help with big clients requiring HSMs or the like.<p>So many cool services could be built with this if there&#x27;s an open API.<p>Edit: Sadly, it seems there&#x27;s no out of the box ELB support... Would be great for TLS termination.
评论 #8598261 未加载
EGregover 10 years ago
Usually when I read &quot;security&quot; and &quot;centralized&quot; in the same sentence, I think of an unsustainable model that will be disrupted in a few years.
nealsover 10 years ago
Lots of new Amazon services today?
评论 #8597908 未加载
评论 #8597904 未加载
lewaldmanover 10 years ago
Could any one point me what&#x27;s wrong with nominal users and keys managed by system automation (AKA Puppet&#x2F;Chef&#x2F;SaltStack)?
评论 #8598359 未加载