Live data from Hacker News

Hackers could have taken over AWS

theregister.co.uk

11–20 of 20 posts

Re: Hackers could have taken over AWS

#11
So we can assume that the cloud security is as strong as the security at weakest link in one of the centralized access component.

Can we have a workflow or multi-level authorizations for critical actions like delete or terminate actions of cloud resources?.

Re: Hackers could have taken over AWS

#12
post #10

Earlier quoted context omitted.

Their focus is on fast user acquisition. So fastest is the best. I wonder how many do care if it's the same account. Like people sleep well with their data on DropBox. Those who care, think and create separate account.

Is DropBox particularly insecure?

I think commenter was just pointing them out as an example of a service that's built on AWS/S3.

Re: Hackers could have taken over AWS

#15
post #10

Earlier quoted context omitted.

Their focus is on fast user acquisition. So fastest is the best. I wonder how many do care if it's the same account. Like people sleep well with their data on DropBox. Those who care, think and create separate account.

Is DropBox particularly insecure?

There was that four hour period earlier this year in which their authentication system defaulted to "allow" for incorrect passwords.

Re: Hackers could have taken over AWS

#17
post #14

Did I miss something, or this basically trying to call out something that Amazon fixed before anyone actually discovered it. Reads like FUD

In other news, Hitler could have won and the terrorists could have successfully followed up 9/11.

I do think this story is noteworthy, not because of the headline, but because it draws attention to the underlying deficiencies of XML cryptography, as others have pointed out in comments.

Re: Hackers could have taken over AWS

#18
post #14

Did I miss something, or this basically trying to call out something that Amazon fixed before anyone actually discovered it. Reads like FUD

The attackers reported the problem to Amazon and allowed Amazon to fix it prior to their public disclosure.

I don't see how that's FUD. There was a problem, they found it, they let Amazon fix it, then they reported what they'd found.

Re: Hackers could have taken over AWS

#19
post #16

WS-* and XML cryptography is such a clusterfuck. It's ironic to see Amazon injured by use of "standard" constructions; they'd have been better off rolling their own here.

You shouldn't really be surprised though; especially after Yegge's rant the other week. Software quality at Amazon is pretty mediocre, and pales in comparison to Google's (I worked at both places.)
Post reply on HN