4 ms·
Yes because they state under the section "Root Cause Analysis" > Ruby Central failed to rotate the AWS root account credentials (password and MFA) after the de
by terracatta 1y ago
Yes because they state under the section "Root Cause Analysis"
> Ruby Central failed to rotate the AWS root account credentials (password and MFA) after the departure of personnel with access to the shared vault.
- sersi 1y agoIf both password and MFA are stored in the same shared vault then MFA's purpose is compromised. Anyone getting access to that shared vault has the full keys to the kingdom the same as if MFA wasn't enabled. Also in this day and age, there's no reason to have the root account creds in a shared vault, no-one should ever need to access the root account, everyone should have IAM accounts with only the necessary permissions.
- deleted 1y ago[deleted]
- blibble 1y ago> If both password and MFA are stored in the same shared vault then MFA's purpose is compromised. Anyone getting access to that shared vault has the full keys to the kingdom the same as if MFA wasn't enabled. absolutely > no-one should ever need to access the root account someone has to be able to access it (rarely) if you're a micro-org having three people with the ability to get it doesn't seem that bad everything else they did is however terrible practice