Live data from Hacker News

Hundreds of exposed Amazon cloud backups found leaking sensitive data

techcrunch.com

41–50 of 73 posts

Re: Hundreds of exposed Amazon cloud backups found leaking sensitive data

#41
post #5

I've been working almost exclusively in the AWS space for about 10 years now. Clients anywhere from tiny little three-person consultancies to Fortune 100. Commercial, govcloud, dozens of clients. Never once have I ever found a use case for making public EBS snapshots. Who on Earth is thinking that it is a good idea to take an EBS snapshot and make it public? Note, several of those engagements did involve multiple acc…

Is it a default setting that it's public or do you have to go out of the way to do that?

Re: Hundreds of exposed Amazon cloud backups found leaking sensitive data

#42
post #5

I've been working almost exclusively in the AWS space for about 10 years now. Clients anywhere from tiny little three-person consultancies to Fortune 100. Commercial, govcloud, dozens of clients. Never once have I ever found a use case for making public EBS snapshots. Who on Earth is thinking that it is a good idea to take an EBS snapshot and make it public? Note, several of those engagements did involve multiple acc…

Laziness in attempting to share data with someone in another org? "Nope, can't access it" ... "Nope, still can't access it"... "My manager is harassing me to get access now"... "Look, just make it public then change it back after I get it copied"...

This 100%. I don't do much AWS stuff - but this issue exists outside of AWS as well (inside a corp).

It's why I hate all the password rotation, double VPN stuff - people work around it too much.

All the old staff start having the tech person track their passwords or write them near the computer, all the young staff use whatever new .io domain does X super easily (but less securely) or stick things on thumb driver (no keypad) or use their personal google drive etc.

Re: Hundreds of exposed Amazon cloud backups found leaking sensitive data

#43
post #16

Earlier quoted context omitted.

Laziness in attempting to share data with someone in another org? "Nope, can't access it" ... "Nope, still can't access it"... "My manager is harassing me to get access now"... "Look, just make it public then change it back after I get it copied"...

goes home completely forgetting to change it back...

The later in the day, the bigger the rationalizations.

At some point you are too stupid to be allowed to use a keyboard. And yet we have an entire culture around staying late to get stuff done that probably could have waited until tomorrow.

Re: Hundreds of exposed Amazon cloud backups found leaking sensitive data

#44

Earlier quoted context omitted.

Oh no. I work with very trendy Silicon Valley folks and it’s always someone in shorts and a t-shirt. Which is to say: it’s definitely a culture issue, but it doesn’t have to be a PHB doing it. I know a lot of really smart people who are under a lot of pressure, and combined with a lack of AWS knowledge, “just make it public” is surprisingly common.

And it's worth noting a nonnegligible percentage of high-achieving businesspeople would torture small animals for the right price. Being a little lax with security policies under pressure isn't so shocking.

How much do you think they'd pay to get to torture small animals?

I had a boss who brought up https://en.wikipedia.org/wiki/The_Mask_of_Sanity and organizational sociopaths about twice a month.

He must have been doing a better job of shielding us from his bosses than I thought, or I've had more crazy bosses than I thought, because a lot of it seemed like normal bureaucratic pathology to me, if a little more intense than usual.

Re: Hundreds of exposed Amazon cloud backups found leaking sensitive data

#45
post #22

Earlier quoted context omitted.

Laziness in attempting to share data with someone in another org? "Nope, can't access it" ... "Nope, still can't access it"... "My manager is harassing me to get access now"... "Look, just make it public then change it back after I get it copied"...

The guy that produces that last line definitely wears a suit.

Nah. "Move fast and break things" usually has an implicit "and bypass all the security, we'll fix it later"

Re: Hundreds of exposed Amazon cloud backups found leaking sensitive data

#47
post #22

Earlier quoted context omitted.

Laziness in attempting to share data with someone in another org? "Nope, can't access it" ... "Nope, still can't access it"... "My manager is harassing me to get access now"... "Look, just make it public then change it back after I get it copied"...

The guy that produces that last line definitely wears a suit.

As much as I dislike the typical suit wearer, the industry as a whole would be much better if IT-people wouldn’t blame everything on them and just tell them you won’t do it. If you are a welder and you boss wants you to weld a gas tank that hasn’t been emptied you tell him that he has no idea what the thing he asks for means, explain why and wait till the gas tank is emptied and everything is checked.

I worked as a Camera guy in film and I am known to be very fast – yet I had directors who wanted things even faster. Bit there is a natural limit to how fast you can get something done without having worthless garbage as a result.

You can take certain risks, skip certain advisable steps, focus on the most essential thing etc, but below that there waits literally nothing.

In my experience taking a step back, breathing in, out, and then proceed to doing it properly is in most cases faster than following your boss into panic and ditching common sense.

It is your responsibility as a professional to say “No” or “Stop” in certain circumstances. And if they really want you to do it, write down the possible consequences of what they force you to do and make them sign that they take the full responsibility.

There is so much talk about IT security with people frowning upon silly behaviour, yet any other craft would bend over backwards before you could force them into unsafe behaviour. If engineers would build bridges like we in IT operate, we would have many collapses a day.

Re: Hundreds of exposed Amazon cloud backups found leaking sensitive data

#48
I had a simple glance in the console and there are like 20,000 exposed ebs snapshots - available for anyone to copy and examine - I think that's only for a single region too - switch regions to see more.

Amazon should make an emergency decision to make all these private.

Sure it will break stuff but I'd be disappointed if Amazon left what is in effect a security hole open for the sake of backwards compatibility.

They should also give me a single click link when I sign in to show me all of my public ebs snapshots and throw it hard in my face when I sign in to the console so I simply cannot avoid seeing them all.

I have multiple AWS accounts and I just signed in to try to see if I have any public EBS snapshots and then I realised I would need to search every single region in every single account and then select every snapshot one by one to find out. That's a huge problem. I need a single click to show me every exposed snapshot across every region in my account.

UPDATE:

I can't say for sure if this is 100% right but I think if you sign in to your AWS account, then click on each of these links, you will find if you have public snapshots.

Maybe someone else could confirm if this is correct?

https://us-east-1.console.aws.amazon.com/ec2/v2/home?region=...

https://us-east-2.console.aws.amazon.com/ec2/v2/home?region=...

https://us-west-1.console.aws.amazon.com/ec2/v2/home?region=...

https://us-west-2.console.aws.amazon.com/ec2/v2/home?region=...

https://ca-central-1.console.aws.amazon.com/ec2/v2/home?regi...

https://eu-central-1.console.aws.amazon.com/ec2/v2/home?regi...

https://eu-west-1.console.aws.amazon.com/ec2/v2/home?region=...

https://eu-west-2.console.aws.amazon.com/ec2/v2/home?region=...

https://eu-west-3.console.aws.amazon.com/ec2/v2/home?region=...

https://eu-north-1.console.aws.amazon.com/ec2/v2/home?region...

https://ap-east-1.console.aws.amazon.com/ec2/v2/home?region=...

https://ap-northeast-1.console.aws.amazon.com/ec2/v2/home?re...

https://ap-northeast-2.console.aws.amazon.com/ec2/v2/home?re...

https://ap-northeast-3.console.aws.amazon.com/ec2/v2/home?re...

https://ap-southeast-1.console.aws.amazon.com/ec2/v2/home?re...

https://ap-southeast-2.console.aws.amazon.com/ec2/v2/home?re...

https://ap-south-1.console.aws.amazon.com/ec2/v2/home?region...

https://me-south-1.console.aws.amazon.com/ec2/v2/home?region...

https://sa-east-1.console.aws.amazon.com/ec2/v2/home?region=...

Re: Hundreds of exposed Amazon cloud backups found leaking sensitive data

#49
post #4

It’s still true that most security issues are caused by human ineptitude, not clever vulnerability-hunting or burning sophisticated zero-days.

Once I mentioned on a mailing list Chrome’s reaction to mouse driver bug on my computer, it would buffer JavaScript events, and process it even for pages on a different domain.

Later I told the EFF I had a suspicion that iOS didn’t rate limit input events to the lock screen, independently a research found out about it a month later.

Even if there are zero days, I don’t think finding them is a particularly noteworthy or rewarding task.

Re: Hundreds of exposed Amazon cloud backups found leaking sensitive data

#50
post #44

Earlier quoted context omitted.

And it's worth noting a nonnegligible percentage of high-achieving businesspeople would torture small animals for the right price. Being a little lax with security policies under pressure isn't so shocking.

How much do you think they'd pay to get to torture small animals? I had a boss who brought up https://en.wikipedia.org/wiki/The_Mask_of_Sanity and organizational sociopaths about twice a month. He must have been doing a better job of shielding us from his bosses than I thought, or I've had more crazy bosses than I thought, because a lot of it seemed like normal bureaucratic pathology to me, if a little more intense t…

There's only one known remedy and it costs 15 cents, so that mask is precious. It's a special gift to be able to see these things clearly, but it comes at the cost of close acquaintance, and you'll always be more watchful than the innocent of mind.

It's grimly amusing how common and relevant psychological aberrance is relative to the average person's perception of it (cf. downvotes). It's tiring and unpleasant to examine the world antagonistically from a place of comfort but luckily others on the fringes don't have an option and force us to pay for prisons and so forth.

Post reply on HN