AWS Security makes an inscrutable choice
Quarantining leaked credentials is not good enough
Amazon Web Services (AWS) has decided not to deactivate leaked root AWS credentials, despite the potential for significant damage. This stance has been criticized, as deactivating these credentials could prevent unauthorized accessing of various AWS services. By quarantining the credentials, AWS aims to limit the potential harm caused by fraud-related activity leading to unauthorized charges, while minimizing the impact on existing resources.
However, many argue that deactivating the credentials is the right decision, as it prevents bad actors from performing various actions such as sending spam via Amazon SNS, modifying EC2 instances, and disabling AWS backup capabilities.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- AWS Security makes an inscrutable choice theregister.com