SRE Weekly Issue #292 • 📖 [The CloudSecList] Issue 109 • [tl;dr sec] #105 - DevSecOps, Ransomware & S3 • Auto Scaling - 1 updated methods • Elastic Load Balancing - 1 updated methods • AWS RoboMaker - 16 updated methods • AWS Config - 12 updated methods • New AWS workbook for New Zealand financial services customers • Introducing the Security at the Edge: Core Principles whitepaper • cloudformation: 1 new condition | 4 updated actions • elasticmapreduce: 9 new actions • servicequotas: 1 updated action • ec2: 7 new conditions | 188 updated actions, 29 updated resources, 1 updated condition | 2 removed conditions • Bypassing required reviews using GitHub Actions - Cider Security - Medium • In 2016, <a href="https://twitter.com/dagrz" target="_blank">@dagrz</a> gave one of the greatest cloud security talks ever, filled with new techniques that have been rediscovered repeatedly in the years since. I've remastered it from video obtained from an audience member and the slide deck. <a href="https://t.co/o0sMXeZPiw" target="_blank">youtube.com/watch?v=8ZXRw4…</a> • The playlist from the conference is now up! <a href="https://t.co/88sFfkAc6Y" target="_blank">youtube.com/playlist?list=…</a> • The <a href="https://twitter.com/fwdcloudsec" target="_blank">@fwdcloudsec</a> 2021 talk videos are now up on YouTube. ☁️🔓📺 Check out all the great speakers from the playlist: <a href="https://t.co/SdqHDdv8vA" target="_blank">youtube.com/playlist?list=…</a> • The Infrastructure as Code rebel alliance are applying a new tactic to discourage use of the console. • 💚I love that in AWS I can have two ongoing email threads with senior leaders. One about critical infrastructure decisions and the other bantering about pumpkin spice everything. Our quirkiness is legit. 🎃☕ • 🗒️ <a href="https://twitter.com/hashtag/Kubernetes" target="_blank">#Kubernetes</a> Security Checklist and Requirements A checklist by <a href="https://twitter.com/vinumsec" target="_blank">@vinumsec</a> covering: * AuthN and AuthZ * Secrets * Cluster config * Auditing and logging * OS config * Network security * Secure configuration of workloads * Securely building images <a href="https://t.co/vZ65pO2qth" target="_blank">github.com/Vinum-Security…</a> • TIL that the AWS Route 53 team: * use exclamation marks in their error messages! * think example[.]com is more deserving of protection than chime[.]aws • Now that GitHub-&gt;AWS OIDC federation is almost here, I want more controls on the AWS side of things. Without them, I don't see large orgs being as enthusiastic about this feature as solo yolo devs. tldr: 1. Trust policy boundaries 2. Claim-tag mappings <a href="https://t.co/8UFPLSmOsa" target="_blank">awsteele.com/blog/2021/10/1…</a> • ⚠️ Risk-Based Security Decision Making at <a href="https://twitter.com/netflix" target="_blank">@netflix</a> This presentation on Thursday sounds 👌 * How Netflix uses risk to make informed decisions * Deep dive into app risk quantification * Using ML to scale expert knowledge * + more H/T <a href="https://twitter.com/travismcpeak" target="_blank">@travismcpeak</a> <a href="https://t.co/UNFx3O6Bkx" target="_blank">eventbrite.com/e/risk-based-s…</a> • Oh man. That feeling when OWASP tweets your name ☺️ feelsgoodman.png Super excited for this talk! • Is the console down? • A chance to do something good while sticking it to AWS? • [New] Network Load Balancer (NLB) now supports TLS 1.3 • How do you get over the learning curve? • Successfully made my first secure static site! (Even used new CloudFront functions to rewrite urls) • Experimenting with TempestSDR. Decoding the "leaking" HDMI signal. Got much higher resolution with a HackRF than with a RTL-SDR • New GitHub vulnerability: Bypassing required reviews using GitHub Actions • Coalfire announces HITRUST Accelerator with AWS Security Assurances Services (AWS SAS) - The Grand Junction Daily Sentinel • 10 Ways to Quickly Improve Security for Your AWS Environment - CPO Magazine
18
Monday October, 2021

📢 MAMIP (Monitor AWS Managed IAM Policies)

Policies changed since last week:

Get notified of policy change using this Twitter bot. 🐦

Auto Scaling - 1 updated methods
Oct 14
Amazon EC2 Auto Scaling now supports filtering describe Auto Scaling groups API using tags
Elastic Load Balancing - 1 updated methods
Oct 14
Adds new option to filter by availability on each type of load balancer when describing ssl policies.
AWS RoboMaker - 16 updated methods
Oct 14
Adding support to GPU simulation jobs as well as non-ROS simulation jobs.
AWS Config - 12 updated methods
Oct 13
Adding Config support for AWS::OpenSearch::Domain
New AWS workbook for New Zealand financial services customers
Julian BusicOct 14
We are pleased to announce a new AWS workbook designed to help New Zealand financial services customers align with the Reserve Bank of New Zealand (RBNZ) Guidance on Cyber Resilience. The RBNZ Guidance on Cyber Resilience sets out the RBNZ expectations for its regulated entities regarding cyber resilience, and aims …
Introducing the Security at the Edge: Core Principles whitepaper
Maddie BaconOct 14
Amazon Web Services (AWS) recently released the Security at the Edge: Core Principles whitepaper. Today’s business leaders know that it’s critical to ensure that both the security of their environments and the security present in traditional cloud networks are extended to workloads at the edge. The whitepaper provides security executives …
cloudformation: 1 new condition | 4 updated actions
Oct 15
1 new condition: cloudformation:TargetRegion (filters access by stack set target region. use to control which regions iam users can use when they create or update stack sets); 4 updated actions: UpdateStackSet (conditions), CreateStackInstances (conditions), DeleteStackInstances (conditions), UpdateStackInstances (conditions)
elasticmapreduce: 9 new actions
Oct 14
9 new actions: AttachEditor (attach an emr notebook to a compute engine), CreatePersistentAppUI (create a persistent application history server), CreateStudioPresignedUrl (launch an emr studio using iam authentication mode), DescribePersistentAppUI (describe a persistent application history server), DescribeReleaseLabel (view information about an emr release, such as which applications are supported), DetachEditor (detach …
servicequotas: 1 updated action
Oct 13
1 updated action: ListTagsForResource (access)
ec2: 7 new conditions | 188 updated actions, 29 updated resources, 1 updated condition | 2 removed conditions
Oct 13
7 new conditions: ec2:AllocationId (filters access by the allocation id of the elastic ip), ec2:Domain (filters access domain of the elastic ip address), ec2:KeyPairType (filters access by a key pair type), ec2:KmsKeyId (filters access by an id of your aws key management service), ec2:Phase2DHGroup (filters access by the diffie-hellman group …
0xdabbad00
Scott Piper @0xdabbad00

In 2016, @dagrz gave one of the greatest cloud security talks ever, filled with new techniques that have been rediscovered repeatedly in the years since. I've remastered it from video obtained from an audience member and the slide deck. youtube.com/watch?v=8ZXRw4…

fwdcloudsec
fwd:cloudsec @fwdcloudsec

The playlist from the conference is now up! youtube.com/playlist?list=…

iann0036
Ian Mckay @iann0036

The @fwdcloudsec 2021 talk videos are now up on YouTube. ☁️🔓📺

Check out all the great speakers from the playlist: youtube.com/playlist?list=…

0xdabbad00
Scott Piper @0xdabbad00

The Infrastructure as Code rebel alliance are applying a new tactic to discourage use of the console.

bjohnso5y
Brigid Johnson @bjohnso5y

💚I love that in AWS I can have two ongoing email threads with senior leaders. One about critical infrastructure decisions and the other bantering about pumpkin spice everything. Our quirkiness is legit. 🎃☕

clintgibler
Clint Gibler @clintgibler

🗒️ #Kubernetes Security Checklist and Requirements

A checklist by @vinumsec covering:
* AuthN and AuthZ
* Secrets
* Cluster config
* Auditing and logging
* OS config
* Network security
* Secure configuration of workloads
* Securely building images

github.com/Vinum-Security…

__steele
Aidan W Steele @__steele

TIL that the AWS Route 53 team:

* use exclamation marks in their error messages!

* think example[.]com is more deserving of protection than chime[.]aws

__steele
Aidan W Steele @__steele

Now that GitHub->AWS OIDC federation is almost here, I want more controls on the AWS side of things.

Without them, I don't see large orgs being as enthusiastic about this feature as solo yolo devs. tldr:

1. Trust policy boundaries
2. Claim-tag mappings

awsteele.com/blog/2021/10/1…

clintgibler
Clint Gibler @clintgibler

⚠️ Risk-Based Security Decision Making at @netflix

This presentation on Thursday sounds 👌

* How Netflix uses risk to make informed decisions
* Deep dive into app risk quantification
* Using ML to scale expert knowledge
* + more

H/T @travismcpeak

eventbrite.com/e/risk-based-s…

kmcquade3
Kinnaird McQuade💥🌩 @kmcquade3

Oh man. That feeling when OWASP tweets your name ☺️ feelsgoodman.png

Super excited for this talk!

owasp
owasp @owasp

On @Owasp_DevSlop, Kinnaird McQuade- @kmcquade3 will go over what sole practitioners need to build out their own "lean but mean" cloud security toolkit. RSVP on Meetup ed.gr/dnw4l
Sponsored by: datadoghq

Is the console down?

Myself and several others are getting 504 when trying to access the console on the east coast.

Anyone else?

edit:

AND WE'RE BACK PEOPLE

edit:

health now shows errors:

8:30 AM PDT We are investigating increased error rates and latencies for the AWS Management Console.

Yeah... latency.

edit: …

A chance to do something good while sticking it to AWS?

Yes, please.

Hi, I’m Corey Quinn. I’m an AWS billing consultant and professional shitposter. Some of you might know me from Last Week In AWS, the snarky newsletter I write. (Some of you don’t know me. You are the lucky ones.)

What a few of you know is that every …

[New] Network Load Balancer (NLB) now supports TLS 1.3

Network Load Balancer (NLB) now supports version 1.3 of the Transport Layer Security (TLS) protocol, enabling you to optimize the performance of your backend application servers while helping to keep your workloads secure. TLS 1.3 on NLB works by offloading encryption and decryption of TLS traffic from your application servers …

How do you get over the learning curve?

I'm a software engineer, I know what ec2, dynamo, rds, elb, and all these services are but when it comes to putting a cloudformation or cdk infra as code script together I just get stuck. The amount of configuration variables and details you need to be aware of are just …

Successfully made my first secure static site! (Even used new CloudFront functions to rewrite urls)

Many of you tried to help me when I was having trouble launching a site, as I'm new to AWS so this post is just an update. The struggle I was having was a certificate request kept timing out. It turns out that because I had deleted and recreated my …

buymeacoffee