5 ms·
Revealing the Inner Structure of AWS Session Tokens
- Chris2048 2y agoHmm, is this structure shared by all AWS-service session tokens? e.g. Amazon-Connect tokens etc.
- QuadmasterXLII 2y agoApparently medium has two seperate “do you want an account” popups now to click out of before you can read. This is a common problem once the development team for a website grows beyond a certain size- the left hand doesn’t know what the right hand is doing. Perhaps we can find the two project leads implementing them, have them fight to the death in some sort of saw trap, and the survivor gets to keep their javascript asking for my email address?
- kevindamm 2y agoNo need for violence if you can A/B test them for conversion rate. I was going to say compete for time to render or ease of dismissal but then I remembered it should be from their reference frame.
- Dachande663 2y agotl;dr it’s a standard protobuf payload after ignoring the first byte.
- Scaevolus 2y agoI'm skeptical of there being any security implications. Signed but not encrypted tokens are effectively plaintext metadata, and token revocation is still an important operation on the service side, preventing zombie token attacks. Reading metadata can be useful to know when a token is expired without hitting a remote service.
- toomuchtodo 2y agohttps://archive.today/2024.07.25-150149/https://medium.com/@TalBeerySec/revealing-the-inner-structure-of-aws-session-tokens-a6c76469cba7 https://archive.today/2024.07.25-150149/https://medium.com/@...
- 1659447091 2y ago> Following this revelation, we were able to observe that these keys change on an hourly basis... Is it recommended to rotate keys hourly, or even daily? Or only for something like AWS - I've read/been told monthly is more than adequate for reg. web apps
- mozman 2y agoyou should provision jit creds via sts - I think default session length if 1hr. dont use hard coded keys and use IRSA.
- watermelon0 2y agoWhen possible, you should not use IAM user long-term credentials. Inside AWS, temporary security credentials via STS should be used. Outside AWS, OIDC federation should be used. Users should use SSO.