Can we have a workflow or multi-level authorizations for critical actions like delete or terminate actions of cloud resources?.
Hackers could have taken over AWS
11–20 of 20 posts
Re: Hackers could have taken over AWS
#12Earlier quoted context omitted.
Their focus is on fast user acquisition. So fastest is the best. I wonder how many do care if it's the same account. Like people sleep well with their data on DropBox. Those who care, think and create separate account.
Is DropBox particularly insecure?
Re: Hackers could have taken over AWS
#13Re: Hackers could have taken over AWS
#14Re: Hackers could have taken over AWS
#15Earlier quoted context omitted.
Their focus is on fast user acquisition. So fastest is the best. I wonder how many do care if it's the same account. Like people sleep well with their data on DropBox. Those who care, think and create separate account.
Is DropBox particularly insecure?
Re: Hackers could have taken over AWS
#16Re: Hackers could have taken over AWS
#17Did I miss something, or this basically trying to call out something that Amazon fixed before anyone actually discovered it. Reads like FUD
I do think this story is noteworthy, not because of the headline, but because it draws attention to the underlying deficiencies of XML cryptography, as others have pointed out in comments.
Re: Hackers could have taken over AWS
#18Did I miss something, or this basically trying to call out something that Amazon fixed before anyone actually discovered it. Reads like FUD
I don't see how that's FUD. There was a problem, they found it, they let Amazon fix it, then they reported what they'd found.
Re: Hackers could have taken over AWS
#19WS-* and XML cryptography is such a clusterfuck. It's ironic to see Amazon injured by use of "standard" constructions; they'd have been better off rolling their own here.