AWS Security makes an inscrutable choice - Corey Quinn

https://image.theregister.com/5291460.jpg?imageId=5291460&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Quarantining leaked credentials is not good enough

One of the best ways to lower your AWS bill by 99 percent or more is by not checking your keys into public GitHub repositories. Many of us have done this inadvertently over the years, and the defenses against it have improved dramatically (my personal favorite being "using non-ephemeral credentials derived from OIDC or SSO is an anti-pattern"), but it still happens.

On Friday, BleepingComputer reported on a Truffle Security finding that hundreds of leaked AWS keys are root keys and are somehow still active and valid.

AWS Security is full of very smart people who care deeply about a number of things, including "not abetting crime." If they detect (usually via automated means) that a credential has been leaked, they're quick to apply a Quarantine Policyto it. Trouble is, that policy enumerates a bunch of bad behaviors in an ever-expanding graph...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more