4 ms·
For those interested, we put the code online here: https://github.com/tracebit-com/find-s3-account https://github.com/tracebit-com/find-s3-account
by tracebit 3y ago
For those interested, we put the code online here: https://github.com/tracebit-com/find-s3-account https://github.com/tracebit-com/find-s3-account
- belter 3y agoI am not sure this would be in agreement with these policies, or at least the spirit of them: https://aws.amazon.com/security/penetration-testing/ https://aws.amazon.com/security/penetration-testing/
- jkaplowitz 3y agoOP's article said they consulted with Amazon's security team before publishing, so I imagine they know what's allowed in this case.
- belter 3y agoIt says he consulted but does not say what was their answer. I can't imagine it was a thumbs up, probably an embarrassed silence?
- willcipriano 3y agoThey can fix the bug if they don't like it.
- Breza 3y agoThis is my attitude towards security disclosures. In this case, Amazon approved the disclosure. But even if they hadn't, it's better for the good guys and bad guys to know about problems when the alternative is only the bad guys knowing (or the bad guys and a few good guys at the affected company).
- chriscjcj 3y agoReminds me of the old slogan for Kix cereal. "Kid Tested. Mother Approved." Kids tested it but we don't know if they approved it. We don't know if mothers tested it; we only know they approved it.
- tracebit 3y agoYes, for the avoidance of doubt - we got the OK from AWS to publish this research
- pests 3y agoWhy all the doubt? "not sure" "can't imagine" When the source says they already did their due diligence...
- belter 3y agoThe initial text was ambiguous but the author has now clarified their answer in this thread. Do you really think they were happy with this? I actually think this might open other attack vectors. I agree that the account number just by itself is not a secret, but there is a reason why all AWS demo videos mask the account number.
- deleted 3y ago[deleted]