4 ms·
Interestingly nobody would be fined by the regulator had the misconfiguration not been discovered by someone stupid enough to to post about it with their real n
by destroy-2A 4y ago
Interestingly nobody would be fined by the regulator had the misconfiguration not been discovered by someone stupid enough to to post about it with their real name, organised criminals would have been smarter about it.
The misconfiguration on a “firewall” sounds like AWS is deep into the capital one org tightly controlling the narrative. Whilst at the end of the day it was an EC2 that had access to all the accounts S3 buckets that was configured to pass out its role token to anyone that asked and the bucket itself had no protection against outside access with a compromised key. This to me sounds like absolute negligence for an FI and rightfully deserves the fine. Back when this attack was done the AWS service made it very complex to mitigate against this type of attack and since then AWS have scrambled to release a bunch of “features” to fix this like Aws:calledvia , s3:resourceaccount condition key, s3 block public access came out just before attack was made public I am sure there were others but this is what I can recall.
- Zombieball 4y ago> and the bucket itself had no protection against outside access with a compromised key Any advice on how to safeguard against this?
- jhugo 4y agoDon't use static keys, and audit access to sensitive resources. If possible, use VPC endpoints and lock down the bucket to only allow access from them.
- addingnumbers 4y ago> Interestingly nobody would be fined by the regulator had the misconfiguration not been discovered by someone stupid enough to to post about it with their real name, organised criminals would have been smarter about it. Isn't there a third option, fully anonymous disclosure by a grey hat? Seems like the best outcome would be from showing it to a scrupulous journalist who protects sources, and it looks like you're discounting that.