RexSystem1 voteoriginally by @DarkRTA on GitHub1 reply
To be honest, this feels like security theater because nothing stops a server admin from disabling the code and reading their own DB anyway.
I guess you could get marginal security improvements in the event of a compromise but I doubt this would be possible to scale up in a secure manner.
yes but it would only be possible to people with access to the encryption keys, which if done correctly (on the main instance) should be just a select few people (vault admins for example), not everyone with access to the database. encryption at rest is definitely helping securing data. on smaller self hosted instances you just have to trust the owner, obviously, same as with plaintext.
Thread
Comment by @DarkRTA
Comment by @tsubus