3 ms·
Unfortunately it's still more common than you think. The other day I actually ran across some AWS docs which suggest you send your AWS root key id in the url o
by ig1 9y ago
Unfortunately it's still more common than you think.
The other day I actually ran across some AWS docs which suggest you send your AWS root key id in the url of http requests:
http://docs.aws.amazon.com/AlexaWebInfoService/latest/index.html?QUERY_QueryRequests.html http://docs.aws.amazon.com/AlexaWebInfoService/latest/index....
- dsmithatx 9y agoWow I didn't believe this at first, so I dug more. AWIS requires the root key of an AWS account. I found a forum that does suggest creating a new account solely for AWIS. https://forums.aws.amazon.com/thread.jspa?threadID=126537 https://forums.aws.amazon.com/thread.jspa?threadID=126537 Still I'm surprised they would suggest sending the root key to your account over http. Even if it is just the id and not secret it still seems like something you want to keep secure. I don't use my root key for services. I create new accounts and IAM roles.