5 ms·
Wow, as someone working on an email service provider startup… this is basically my worst nightmare. On the upside, the tooling around infrastructure has improv
by Felz 8y ago
Wow, as someone working on an email service provider startup… this is basically my worst nightmare.
On the upside, the tooling around infrastructure has improved so much since vfemail launched in 2001 that there's a lot more I can do. With AWS, I can do automatic database backups, S3 bucket delete versioning, IAM auditing, whitelist firewalls, etc.
- wcoenen 8y ago> With AWS, I can do... Can you remotely delete all the data and backups? (It's an honest question; I'm not intimately familiar with AWS but from glancing at the documentation it seems that even glacier archives can be deleted without delay) Because if you can, then so can an attacker who has sufficiently compromised your business. edit: I see some stuff about "vault locking" which might do the trick. Are you using that to protect your data?
- Felz 8y agoYep, AWS doesn't seem to have any time-lock delete mechanisms as far as I know, which is a shame. I still have to research this, but as far as I can tell the best practice seems to be using MFA delete: https://docs.aws.amazon.com/AmazonS3/latest/dev/Versioning.html#MultiFactorAuthenticationDelete https://docs.aws.amazon.com/AmazonS3/latest/dev/Versioning.h... And then keeping root user credentials on a cold storage laptop. Vault lock seems to be for Glacier, but it'd still be worth looking into for cold storage backups. More layers of defense are always good.
- xfitm3 8y agoYou can also use S3 legal hold in compliance mode, although, I'm not sure how you would eventually delete it. "S3 Object Lock can be configured in one of two modes. When deployed in Governance mode, AWS accounts with specific IAM permissions are able to remove object locks from objects. If you require stronger immutability to comply with regulations, you can use Compliance Mode. In Compliance Mode, the protection cannot be removed by any user, including the root account." https://aws.amazon.com/about-aws/whats-new/2018/11/s3-object-lock/ https://aws.amazon.com/about-aws/whats-new/2018/11/s3-object...