AWS Security makes an inscrutable choice
Quarantining leaked credentials is not good enough
AWS Security has made a perplexing decision regarding the handling of leaked AWS keys. According to Truffle Security, hundreds of root keys are still active and valid despite being leaked. While AWS Security has a team of intelligent, security-conscious individuals, their approach to quarantining these keys has come under scrutiny.
When a credential is detected as leaked, AWS Security swiftly applies a Quarantine Policy to it. This policy is designed to mitigate potential damage from fraud-related activity, such as unauthorized charges. However, AWS Security's stance is that they do not wish to disrupt customer environments. They explain that their policy aims to "limit the potential damage that may be caused by fraud-related activity leading to unauthorized charges, while not impacting the existing resources."
Critics argue that this approach is misguided. If an attacker gains access to your credentials, deactivating them could disrupt your workloads, as anything relying on those credentials would cease to function. This could lead to significant operational issues for the affected customers.
While AWS Security's quarantine policy may prevent certain actions, it fails to block others that could be harmful. For instance, attackers can still execute commands as root on EC2 instances, assume other roles in the account, launch instances via Auto Scaling service-linked roles, delete audit logs, send fraudulent emails, send SMS messages, delete objects in S3 buckets, enable versioning and object lock configurations in S3, and more.
Moreover, AWS Security's decision to allow the deletion of backup recovery points and database snapshots could lead to data loss for customers who rely on these backups. Additionally, the lack of enforcement on secret management actions, such as GetSecretValue, GetParameter* (WithDecryption), and Decrypt, leaves customers' secrets vulnerable to theft.
Critics question how large an incident would need to be for AWS Security to reconsider their approach. They urge the company to consider the potential impact of a customer incident before applying a quarantine policy.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- AWS Security makes an inscrutable choice theregister.com