4 ms·
kind of terrifying.. wonder how long until a script kiddy finds some access/secret keys in github or somewhere else and kills a company.
by boston_sre87 6y ago
kind of terrifying.. wonder how long until a script kiddy finds some access/secret keys in github or somewhere else and kills a company.
- cddotdotslash 6y agoIt's definitely already happened [1] (5 years ago at that). It usually involves some kind of ransom as well. [1] https://www.infoworld.com/article/2608076/murder-in-the-amazon-cloud.html https://www.infoworld.com/article/2608076/murder-in-the-amaz...
- arkadiyt 6y agoThey could do the same by using the access keys directly - using this service is strictly better since it would identify the attacker by their Stripe payment method.
- nthacker 6y agoExactly
- boston_sre87 6y agoYea, agreed.. they definitely could assuming someone does something stupid and exposes keys with access to everything. But this removes the barrier of needing to have a tiny bit of technical knowledge to do it. I think pastebin post with the cloudnuke url, keys, and a stolen credit card would look pretty appetizing for bored people. I'm not saying this shouldn't exist exactly.. maybe some kind of additional identity verification would make it less scary tho.
- wrboyce 6y agoThe same pastebin could exist today by simply providing a script alongside the access keys, I don't see how this paid-for service changes anything aside adding an extra hurdle.
- hcazz 6y agoRelying on a cheap payment online to identify an individual determined to act maliciously likely isn't going to lead anywhere useful.