{
  "id": 2518120,
  "title": "AWS Security makes an inscrutable choice",
  "url": "https://urgent.news/2026/08/21/aws-security-makes-an-inscrutable-choice",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-21T23:42:41.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/08/22/aws-security-makes-an-inscrutable-choice-corey-quinn/5291446"
  },
  "original_language": "en",
  "account": "AWS Security has made a perplexing decision regarding the handling of leaked AWS keys. According to Truffle Security, hundreds of root keys are still active and valid despite being leaked. While AWS Security has a team of intelligent, security-conscious individuals, their approach to quarantining these keys has come under scrutiny.\n\nWhen a credential is detected as leaked, AWS Security swiftly applies a Quarantine Policy to it. This policy is designed to mitigate potential damage from fraud-related activity, such as unauthorized charges. However, AWS Security's stance is that they do not wish to disrupt customer environments. They explain that their policy aims to \"limit the potential damage that may be caused by fraud-related activity leading to unauthorized charges, while not impacting the existing resources.\"\n\nCritics argue that this approach is misguided. If an attacker gains access to your credentials, deactivating them could disrupt your workloads, as anything relying on those credentials would cease to function. This could lead to significant operational issues for the affected customers.\n\nWhile AWS Security's quarantine policy may prevent certain actions, it fails to block others that could be harmful. For instance, attackers can still execute commands as root on EC2 instances, assume other roles in the account, launch instances via Auto Scaling service-linked roles, delete audit logs, send fraudulent emails, send SMS messages, delete objects in S3 buckets, enable versioning and object lock configurations in S3, and more.\n\nMoreover, AWS Security's decision to allow the deletion of backup recovery points and database snapshots could lead to data loss for customers who rely on these backups. Additionally, the lack of enforcement on secret management actions, such as GetSecretValue, GetParameter* (WithDecryption), and Decrypt, leaves customers' secrets vulnerable to theft.\n\nCritics question how large an incident would need to be for AWS Security to reconsider their approach. They urge the company to consider the potential impact of a customer incident before applying a quarantine policy.",
  "summary": "Quarantining leaked credentials is not good enough",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "AWS Security makes an inscrutable choice",
        "url": "https://urgent.news/2026/08/21/aws-security-makes-an-inscrutable-choice-2520651",
        "published": "2026-08-21T23:42:41.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}