Amazon DynamoDB encrypts all customer data at rest

Okay, (maybe) dumb question then: Why is this not just a standard part of the overall platform? Encrypt the drives at rest so AWS employees can't access it, add some additional access logging functionality for those who need it, then everyone is secure and only people with a regulatory requirement to manage their own keys would need to use this service.

From the way it looks this isn't giving folks a ton of actual security over what you could otherwise do with IAM policies. It just makes it harder for AWS employees to get access to the data. Which I'd imagine would be something AWS would want to stop for everyone regardless of which service they use.

/r/aws Thread Parent Link - aws.amazon.com