Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

With banks considering the switch to the Cloud, how would this specification address the issue of key management on the Cloud? That's the "key" to Cloud security. Currently, there are solutions available which are obnoxious for those who <i>really</i> want security of their data and not just a <i>tick mark</i> on some data security checklist because key managers CANNOT be hosted on the Cloud. The dominant approach (CipherCloud for example) is to have an encryption gateway in-house which encrypts/decrypts/tokenizes on-the-fly before data leaves for the Cloud. Their approach is to enable support for popular SaaS apps like SalesForce and archive storage like S3 etc which makes sense BUT then again, it's dependent on whether the vendor would add support for more apps or open the API for 3rd party devs to plug in support for other Cloud apps.


A networked HSM is certainly one approach to solving this. Often, corporations -- not just banks or financial institutions -- will rent a cage in the same data center as the cloud provider, and will run a dedicated line from their cage to the provider. The networked HSM will store all key material, and whatever sensitive servers/databases/applications are provisioned in the cloud will leverage it for cryptographic operations.

In theory... 1) The keys never leave the physically-hardened HSM, so they're "safe", 2) Transmission between the HSM clients and the HSM is done over an encrypted channel, so that's "safe"

There's always a very high risk of implementing things improperly and negating any security benefits of this type of setup, but that risk exists with on-prem infrastructures, too.


You forgot to capitalize "Cloud".




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: