Urgent.News

What's breaking now, across thousands of outlets.

Tech

How to explain protecting the AWS root user and everyday admin access in an interview

The interviewer leans back and asks: "You've just created a new AWS account. What's the first thing you do about security?" Many freshers answer "enable MFA" and stop there. That answer is correct, but it is incomplete. A complete answer has two halves. First, lock the root user: give it a strong password and multi-factor authentication, create no access keys for it, and control who can recover…

The interviewer asks what the first security step is after creating a new AWS account. Many candidates respond by mentioning enabling multi-factor authentication (MFA), but a complete answer involves two parts. First, securing the root user, then putting it out of immediate use.

The root user has full access to every resource in the account. AWS advises against using the root user for everyday tasks. Think of the root user like the master key to a building - you don't keep it on your keyring for daily use. Instead, you lock it away in a safe and only use a key cut for specific doors.

To secure the root user's credentials, create a strong, unique password and enable MFA. AWS recommends using a password manager to generate strong passwords. The password must be 8 to 128 characters long and include uppercase letters, lowercase letters, numbers and symbols. It cannot match the account name or email. MFA adds an extra layer of security.

AWS supports hardware security keys, six-digit time-based one-time passwords, and virtual authenticator apps on a phone. It's crucial to register more than one MFA device for added resilience. If you lose the only device, you'll need to contact customer service to remove MFA.

Don't create access keys for the root user. These keys provide full access to all services and resources, including billing information. Root access keys are rarely needed, so AWS recommends using a separate administrative identity for everyday work. Assume temporary credentials instead of using long-term root keys. Roles have no long-term credentials and provide temporary security credentials when assumed.

Only people with a strict business need should have access to the root user's credentials. Don't share the root password, MFA, access keys or signing certificate.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

What 508 Users Taught a Tiny Startup About Its Own Product

Last month, 508 people used Proxyceptor for the first time. We're a small team, so that number means a lot to us. But the numbers that taught us the most weren't the flattering ones.

  • Proxyceptor gained 508 users in first month, significant for small team
  • Microsoft Clarity provided detailed user behavior insights without sampling
  • 38% of users made 38 sessions each, indicating strong return rate

peep: an offline bird ID that runs entirely on your phone!

This is a submission for the Hacktoberfest Open-Source AI Challenge Week 1: Touch Grass What I Built You're on a walk and something in a tree is singing.

  • Offline bird ID app runs entirely on smartphone
  • Identify birds by song or photo without internet
  • Free app, no data upload or payment required

SMS Notification Services Explained: Polling, Suppressions, and Batch Alerts in 2026

Integration effort is the deciding trade-off for a volunteer-coordination app. A plain REST API with polling keeps the dependency surface small; a provider with delivery webhooks adds setup, but it…

  • Polling model with REST API minimizes dependencies for volunteer-coordination app
  • Webhook delivery preferred for immediate reactions to failed text or batch alerts
  • Infrai recommended for single-send, batch-send, and suppression features

More from Sunday 11 October →