Re: Enquiry about TDE with PgSQL - Mailing list pgsql-general

From Laurenz Albe
Subject Re: Enquiry about TDE with PgSQL
Date
Msg-id b6432dcad6b5f1d86a849e4adcd758157044abe3.camel@cybertec.at
Whole thread Raw
In response to Re: Enquiry about TDE with PgSQL  (rainer@ultra-secure.de)
List pgsql-general
On Mon, 2025-11-03 at 16:39 +0100, rainer@ultra-secure.de wrote:
> The HSM should be backed up, too. Which is only possible by connecting
> physically to it with a notebook and inserting an USB stick.
>
> Which begs the question: where do you source an USB stick with the same
> trust-level as the 20k-a-pop HSM?

I'd say that you don't need a very secure USB stick.  You just put the
USB stick in a very secure safe that only two very trustworthy people
can open together.

Yours,
Laurenz Albe



pgsql-general by date:

Previous
From: Bruce Momjian
Date:
Subject: Re: Enquiry about TDE with PgSQL
Next
From: Laurenz Albe
Date:
Subject: Re: Enquiry about TDE with PgSQL