SRE Weekly Issue #355 • [tl;dr sec] #164 - Becoming Phishless, Machine Learning • AWS Clean Rooms Service - 34 new methods • AWS Lambda - 5 updated methods • AWS Elemental MediaConvert - 11 updated methods • AWSKendraFrontendService - 1 updated methods • Three key security themes from AWS re:Invent 2022 • Recap to security, identity, and compliance sessions at AWS re:Invent 2022 • elasticmapreduce: 1 new action • cleanrooms: 34 new actions, 4 new resources • iam: 11 new actions • Taking The New Secrets Manager Lambda Extension For a Spin • Update detected · z0ph/MAMIP@55573d4 • CircleCI incident report for January 4, 2023 security incident • the call i'm on just called a floppy disk "the save icon" and i guess i'll go die of old age now • ✅ How to *actually* roll out YubiKeys/WebAuthN Industry advice is to "just do it" But it's actually really hard in practice 8 resources on lessons learned from companies who've done it 🧵 • 🦀 Memory Safe Languages in Android 13 To date, 0 memory safety vulns in Android’s Rust code Historical vulnerability density is &gt;1/kLOC in C/C++ components → Rust has already prevented 100s of vulns By <a href="https://twitter.com/jeffvanderstoep" target="_blank">@jeffvanderstoep</a> <a href="https://t.co/DzpULTSoCC" target="_blank">security.googleblog.com/2022/12/memory…</a> • My neighbor works in finance and is required to take a minimum amount of no-contact PTO every year. It ensures there's organizational resilience and it's even seen as a check on fraud. Unlimited PTO would be better with measures like that included ... enforce a minimum. • If you're interested in permissions management and authorization, check out my new blog post on the new Cedar language - currently integrated into Amazon Verified Permissions and <a href="https://twitter.com/hashtag/AWS" target="_blank">#AWS</a> Verified Access, and more in the future. 🌲🔐 <a href="https://t.co/CSkuNrhmx5" target="_blank">onecloudplease.com/blog/cedar-a-n…</a> • How many different AWS phishing vectors are you aware of? I found four - anything I missed? <a href="https://t.co/bjot6aF0cP" target="_blank">ramimac.me/aws-phishing</a> • 12 years clean and sober today 😊 • Do you work somewhere that uses Github Enterprise Cloud, but doesn't use GitHub Actions OIDC because it's not possible for AWS org admins to lock down role creation to only your GitHub Enterprise? I wrote this for you. ✨Fancy✨ screenshot for the tl;dr <a href="https://t.co/122SRICQXx" target="_blank">awsteele.com/blog/2023/01/1…</a> • A good example of threat lists in CI/CD: <a href="https://t.co/m0QBo5DmY0" target="_blank">storage.googleapis.com/prd-engineerin…</a> This 👆 is part of the worth-reading article: <a href="https://t.co/x9kN1KQpe5" target="_blank">engineering.mercari.com/en/blog/entry/…</a> by <a href="https://twitter.com/MercariDev" target="_blank">@MercariDev</a> • “Just use Kubernetes” 🙄 • AWS Lambda now supports Maximum Concurrency for Amazon SQS as an event source • META: How do we feel about the blog "spam?" • AWS Network Firewall adds support for reject action for TCP traffic • AWS Clean Rooms is now available in preview • Accelerate FedRAMP Compliance with Amazon Web Services (AWS) - Security Boulevard • AWS security heads offer top cybersecurity predictions for 2023 - VentureBeat • AWS IP Ranges update for 2023-01-05 06:03:06 • AWS IP Ranges update for 2023-01-05 07:43:09

ASD Logo

16
Monday January, 2023

Sponsor

unusd.cloud helps you reduce your environmental impact 🍃 by identifying and shutting down mistakenly active assets, lowering your security risks 🔒, and decreasing your AWS bills 🗒️.

Don’t let unused assets drain your AWS budget.

It's free (forever) for a single AWS Account.

In a nutshell

From last week: AWS just made security a top priority by default. S3 now automatically encrypts all new objects with SSE-S3. This change puts another security best practice into effect automatically, with no impact on performance & no action required on your side. Existing buckets using S3 default encryption will not change.

AWS Clean Rooms Service - 34 new methods
Jan 12
Initial release of AWS Clean Rooms
AWS Lambda - 5 updated methods
Jan 12
Add support for MaximumConcurrency parameter for SQS event source. Customers can now limit the maximum concurrent invocations for their SQS Event Source Mapping.
AWS Elemental MediaConvert - 11 updated methods
Jan 12
The AWS Elemental MediaConvert SDK has added support for compact DASH manifest generation, audio normalization using TruePeak measurements, and the ability to clip the sample range in the color corrector.
AWSKendraFrontendService - 1 updated methods
Jan 11
This release adds support to new document types - RTF, XML, XSLT, MS_EXCEL, CSV, JSON, MD
Three key security themes from AWS re:Invent 2022
Anne GrahnJan 13
AWS re:Invent returned to Las Vegas, Nevada, November 28 to December 2, 2022. After a virtual event in 2020 and a hybrid 2021 edition, spirits were high as over 51,000 in-person attendees returned to network and learn about the latest AWS innovations. Now in its 11th year, the conference featured …
Recap to security, identity, and compliance sessions at AWS re:Invent 2022
Katie CollinsJan 13
AWS re:Invent returned to Las Vegas, NV, in November 2022. The conference featured over 2,200 sessions and hands-on labs and more than 51,000 attendees over 5 days. If you weren’t able to join us in person, or just want to revisit some of the security, identity, and compliance announcements and …
elasticmapreduce: 1 new action
Jan 14
1 new action: GetClusterSessionCredentials (Grants permission to retrieve HTTP basic credentials associated with a given execution IAM Role for a fine-grained access control enabled EMR Cluster)
cleanrooms: 34 new actions, 4 new resources
Jan 14
34 new actions: BatchGetSchema (Grants permission to view details for schemas), CreateCollaboration (Grants permission to create a new collaboration, a shared data collaboration environment), CreateConfiguredTable (Grants permission to create a new configured table), CreateConfiguredTableAnalysisRule (Grants permission to create a analysis rule for a configured table), CreateConfiguredTableAssociation (Grants permission to link …
iam: 11 new actions
Jan 14
11 new actions: DeleteCloudFrontPublicKey (Grants permission to delete an existing CloudFront public key), GetAccountEmailAddress (Grants permission to retrieve the email address that is associated with the account), GetAccountName (Grants permission to retrieve the account name that is associated with the account), GetCloudFrontPublicKey (Grants permission to retrieve information about the specified …
abbyfuller
Abby Fuller @abbyfuller

the call i'm on just called a floppy disk "the save icon" and i guess i'll go die of old age now

30Jan 12 · 4:28 PM
clintgibler
Clint Gibler @clintgibler

✅ How to *actually* roll out YubiKeys/WebAuthN

Industry advice is to "just do it"

But it's actually really hard in practice

8 resources on lessons learned from companies who've done it 🧵

60Jan 11 · 5:00 PM
clintgibler
Clint Gibler @clintgibler

🦀 Memory Safe Languages in Android 13

To date, 0 memory safety vulns in Android’s Rust code

Historical vulnerability density is >1/kLOC in C/C++ components → Rust has already prevented 100s of vulns

By @jeffvanderstoep

security.googleblog.com/2022/12/memory…

27Jan 09 · 5:00 PM
colmmacc
Colm MacCárthaigh @colmmacc

My neighbor works in finance and is required to take a minimum amount of no-contact PTO every year. It ensures there's organizational resilience and it's even seen as a check on fraud. Unlimited PTO would be better with measures like that included ... enforce a minimum.

film_girl
Christina Warren @film_girl

FTR, unlimited PTO is a scam and we all know it.

7Jan 12 · 10:37 PM
iann0036
Ian Mckay @iann0036

If you're interested in permissions management and authorization, check out my new blog post on the new Cedar language - currently integrated into Amazon Verified Permissions and #AWS Verified Access, and more in the future. 🌲🔐

onecloudplease.com/blog/cedar-a-n…

25Jan 11 · 9:34 AM
ramimacisabird
rami @ramimacisabird

How many different AWS phishing vectors are you aware of?

I found four - anything I missed?

ramimac.me/aws-phishing

22Jan 09 · 7:46 PM
__steele
Aidan W Steele @__steele

Do you work somewhere that uses Github Enterprise Cloud, but doesn't use GitHub Actions OIDC because it's not possible for AWS org admins to lock down role creation to only your GitHub Enterprise?

I wrote this for you. ✨Fancy✨ screenshot for the tl;dr

awsteele.com/blog/2023/01/1…

11Jan 11 · 5:34 AM
Rzepsky
Pawel Rzepa @Rzepsky

A good example of threat lists in CI/CD: storage.googleapis.com/prd-engineerin…

This 👆 is part of the worth-reading article: engineering.mercari.com/en/blog/entry/… by @MercariDev

10Jan 10 · 9:42 AM
steven_bryen
Steven Bryen @steven_bryen

“Just use Kubernetes” 🙄

8th_block
Dmitry M @8th_block

@dhh Running your own infra on your own metal has never been easier! Just use Kubernetes. You can find a better open sourced version of practically every AWS product. Even Lambdas

5Jan 13 · 8:47 PM
META: How do we feel about the blog "spam?"

Personally, it drives me up the wall. I feel like 9/10 times a post from /r/aws ends up in my front page, it's just a link to an article with zero comments, no discussion to be had, etc.

I'd feel a lot better about these sorts of posts if the …