Erich
(Erich Kuba)
2
One solution to the above is to not project any encrypted fields in queries that might cross DEK boundaries. If you’re within one DEK boundary, it would make sense to throw the exception.
Of course, another solution is to delete the data itself, but that could be easier said than done on a large micro-serviced platform [anyway, that was out of scope for this discussion].
I’d be interested to hear any other proposals.