Live data from Hacker News

Shattering the rotation illusion: The attacker view and AWSKeyLockdown (2024)

clutch.security

1–5 of 5 posts

Re: Shattering the rotation illusion: The attacker view and AWSKeyLockdown (2024)

#4
Reality is that a string of letters and numbers in plain text is all that’s required to grant someone full root access to your AWS (and many other cloud) provider’s existence even if all your stuff is disconnected from the internet.

Lots of best practices to mitigate the risk of that and blast radius of a comprise, but it’s a nasty anti-pattern in cloud security that bites hard when things go wrong. As the article highlights attackers are well positioned to exploit this and can take over your assets in seconds after an oops.

Re: Shattering the rotation illusion: The attacker view and AWSKeyLockdown (2024)

#5
post #4

Reality is that a string of letters and numbers in plain text is all that’s required to grant someone full root access to your AWS (and many other cloud) provider’s existence even if all your stuff is disconnected from the internet. Lots of best practices to mitigate the risk of that and blast radius of a comprise, but it’s a nasty anti-pattern in cloud security that bites hard when things go wrong. As the article hi…

If you aren’t using 2FA for your root account, then you are asking to be compromised.