| ▲ | Agingcoder 12 hours ago | ||||||||||||||||
Thanks. I get that FHE is not realistic today, but can’t I use ( if it’s really critical) a combination of confidential vms and an external hsm ? I understand I’ll be limited to traditional workloads , and not managed services though. I asked the wrong question, what I really meant was ‘if I run in a less trusted environment, am I not supposed to use all possible crypto mechanisms available to make that environment more trustworthy , so that I can’t be deceived by my cloud operator sending my data to the us government’ | |||||||||||||||||
| ▲ | fragmede 5 hours ago | parent [-] | ||||||||||||||||
That's just not possible. It's why detractors never got on board with the Cloud. Until FHE is feasible, the decryption keys and plaintext have to exists in RAM eventually at some point in order even if only took be re-encrypted, if any complex work is to be done on it. Because eg, Amazon, has access to your hardware, there's simply no way to prevent them from reading your secrets out of your VM that's using their RAM. Absolutely do what you can, but understand that it's futile to defend against your own cloud provider. | |||||||||||||||||
| |||||||||||||||||