I'm bit newbie on AWS, and my mission is to make sure all the data in RDS's specific database encrypted.
I created sample RDS db instance with encryption enabled, (and make it accessible globally in order to simulate exploitation procedure).
Then, once I created the DB instance, with mysql-client, when I access to the data,
+---------+---------+
| column1 | column2 |
+---------+---------+
| orange | hawaii |
+---------+---------+
all the data is not cipher text but plaintext. I expected something like this:
+----------+---------+
| column1 | column2 |
+----------+---------+
| abj12b7 | bb2ce11 |
+----------+---------+
plus, also when mysqldump tried, i can get raw data.
So my question is: what this RDS's encryption option is for? How to confirm that the data in RDS are encrypted and in which workflow this encryption assures of your safety? Actually, not sure how this encryption works.... because i can see plain text data with usual mysql-client access....
Are there any conceivable risks or exploit scenario when i don't encrypt storage in RDS?