4 ms·
I started treating long random bucketnames as secrets years ago. Ever since I noticed hackers were discovering buckets online with secrets and healthcare info.
by INTPenis 7mo ago
I started treating long random bucketnames as secrets years ago. Ever since I noticed hackers were discovering buckets online with secrets and healthcare info.
This is where IaC shines.
- XorNot 7mo agoI just started using hashes for names. The deployment tooling knows the "real" name. The actual deployment hash registers a salt+hash of that name to produce a pseudo-random string name.
- Galanwe 7mo agoThis is all good and we'll on the IaC side,yes. But at the end of the day, buckets are also user facing resources, and nobody likes random directory / bucket names.
- amluto 7mo agoIt would be nice if the other end of this could be addressed: a configurable policy to limit resolution of bucket names within an account namespace. Ideally, if someone doesn’t have permission to resolve a bucket name, they shouldn’t even be able to detect whether it exists.
- INTPenis 7mo agoThat's a contradiction, a bucket name being treated as a secret in IaC, while being a user facing resource. So no, they're not user facing resources. If anyone wants them to be user facing resources, then treat them as such, and ensure they're secure, and don't store sensitive info on them. Otherwise, put a service infront of them, and have the user go through it. The S3 protocol was meant to make the lives of programmers easier, not end users.
- deleted 7mo ago[deleted]
- 8organicbits 7mo ago~As far as I know, bucket names are public via certificate transparency logs.~ There are tools for collecting those names. Besides you'd leak the subdomain to (typically) unencrypted DNS when you do a lookup and maybe via SNI. Edit: crossout incorrect info
- BCM43 7mo agoI'm pretty sure buckets use star certs and thus the individual bucket names won't be in the transparency logs.
- 8organicbits 7mo agoAh you're right, they are always wildcard certs. I think I was mis-remembering https://news.ycombinator.com/item?id=15826906 https://news.ycombinator.com/item?id=15826906, which guesses names based on CT logs. In either case, the subdomain you use in DNS requests are not private. Attackers can collect those from passive DNS logs or in other ways.
- embedding-shape 7mo ago> Besides you'd leak the subdomain to (typically) unencrypted DNS when you do a lookup and maybe via SNI. "Leak" is maybe a bit over-exaggerated, although if someone MitM'd you they definitely be able to see it. But "leak" makes it seem like it's broadcasted somehow, which obviously it isn't.
- 8organicbits 7mo agoNo man-in-the-middle is needed, DNS queries are often collected into large datasets which can be analyzed by threat hunters or attackers. Check out passive DNS https://www.spamhaus.com/resource-center/what-is-passive-dns-a-beginners-guide/ https://www.spamhaus.com/resource-center/what-is-passive-dns... You'd need to check the privacy policy of your DNS provider to know if they share the data with anyone else. I've commonly seen source IP address consider as PII, but not the content of the query. Cloudflare's DNS, for example, shares queries with APNIC for research purposes. https://developers.cloudflare.com/1.1.1.1/privacy/public-dns-resolver/#limited-data-sharing-with-apnic https://developers.cloudflare.com/1.1.1.1/privacy/public-dns... Other providers share much more broadly.