Live data from Hacker News

Hackers could have taken over AWS

theregister.co.uk

1–10 of 20 posts

Re: Hackers could have taken over AWS

#3
post #2

I do find it odd that they encourage you to use the same account to sign into Amazon the store and AWS. That seems a bit like asking for a Subway loyalty card to buy a gun.

When did they start doing that? When I started using S3 to back up other people's photos I immediately created a second Amazon account for AWS. I don't remember them discouraging me from doing that.

Re: Hackers could have taken over AWS

#4
post #3
post #2

I do find it odd that they encourage you to use the same account to sign into Amazon the store and AWS. That seems a bit like asking for a Subway loyalty card to buy a gun.

When did they start doing that? When I started using S3 to back up other people's photos I immediately created a second Amazon account for AWS. I don't remember them discouraging me from doing that.

What I meant was that if you use the email registered for amazon.com when signing up to AWS they don't create a separate account for you or suggest that you use a different e-mail to create a new account.

Re: Hackers could have taken over AWS

#5
post #4
post #3

Earlier quoted context omitted.

When did they start doing that? When I started using S3 to back up other people's photos I immediately created a second Amazon account for AWS. I don't remember them discouraging me from doing that.

What I meant was that if you use the email registered for amazon.com when signing up to AWS they don't create a separate account for you or suggest that you use a different e-mail to create a new account.

That's a good point. I suppose it's not surprising, though, that they streamline the signup process for a service that they charge for.

Re: Hackers could have taken over AWS

#6
post #2

I do find it odd that they encourage you to use the same account to sign into Amazon the store and AWS. That seems a bit like asking for a Subway loyalty card to buy a gun.

From the article, one problem is that even if you don't use your AWS account on the Amazon store, you could, and so XSS vulnerabilities in the store can be used to hijack AWS accounts. Unfortunately the store is large and complex and so has a large attack surface area.

Re: Hackers could have taken over AWS

#7
post #4
post #3

Earlier quoted context omitted.

When did they start doing that? When I started using S3 to back up other people's photos I immediately created a second Amazon account for AWS. I don't remember them discouraging me from doing that.

What I meant was that if you use the email registered for amazon.com when signing up to AWS they don't create a separate account for you or suggest that you use a different e-mail to create a new account.

Their focus is on fast user acquisition. So fastest is the best.

I wonder how many do care if it's the same account. Like people sleep well with their data on DropBox.

Those who care, think and create separate account.

Re: Hackers could have taken over AWS

#9
post #6
post #2

I do find it odd that they encourage you to use the same account to sign into Amazon the store and AWS. That seems a bit like asking for a Subway loyalty card to buy a gun.

From the article, one problem is that even if you don't use your AWS account on the Amazon store, you could , and so XSS vulnerabilities in the store can be used to hijack AWS accounts. Unfortunately the store is large and complex and so has a large attack surface area.

Amazon offer security token authentication for accessing AWS account resources, which can limit the impact of a breach in another part of their system.

Re: Hackers could have taken over AWS

#10
post #4

Earlier quoted context omitted.

What I meant was that if you use the email registered for amazon.com when signing up to AWS they don't create a separate account for you or suggest that you use a different e-mail to create a new account.

Their focus is on fast user acquisition. So fastest is the best. I wonder how many do care if it's the same account. Like people sleep well with their data on DropBox. Those who care, think and create separate account.

Is DropBox particularly insecure?
Post reply on HN