1
Ask HN: Why use cloud service (e.g. S3) encryption at rest?
The key is stored in the same system somewhere (or your app wouldn't function). A rogue employee can find the key if they want. Is there a practical benefit other than additional compliance checkboxes being checked?