WebApp Sec mailing list archives

Encrypted storage


From: Jeffrey Koniszewski <jkoniszewski () kronos com>
Date: 8 Sep 2004 20:38:53 -0000



I was wondering (because customers have asked me) whether anyone is configuring their database to store all information 
encrypted. Databases have this capability but the overhead can be so heavy that vendors don't recommend using it 
generically. Also, if most of the data is not sensitive it is a lot of work to protect small amounts of data. Is anyone 
aware of someone using this capability? Under what circumstances? What's the performance hit? What other gotchas? How 
about encrypted communication to the DB from the app server?


Current thread: