SRE Weekly Issue #295 • 📖 [The CloudSecList] Issue 112 • [tl;dr sec] #108 - How SolarWinds is Securing their Supply Chain, Cloud Security Tooling • AWS Security Hub adds support for AWS PrivateLink for private access to Security Hub APIs • AWS Secrets Manager increases secrets limit to 500K per account • Amazon Chime SDK Meetings - 11 new methods • Amazon Connect Service - 5 new methods • Amazon Elastic Compute Cloud - 4 updated methods • AWS IoT Wireless - 26 new 3 updated methods • Implement OAuth 2.0 device grant flow by using Amazon Cognito and AWS Lambda • The Five Ws episode 2: Data Classification whitepaper • securityhub: 5 new actions, 1 new resource • servicequotas: 1 updated condition • iotwireless: 26 new actions, 2 new resources • permissions.cloud • No more making Lambda@Edge functions just to add HTTP headers to CloudFront. <a href="https://t.co/sBaFMR2FfJ" target="_blank">github.com/aws/aws-sdk-go…</a> • I think there's no need for AWS IAM users today. So I made a PoC to "prove" it. First here are the general use-cases for creds * AWS SSO works great for humans 👍 * Roles work fine inside AWS 👍 * Federation works fine from other clouds 👍 * Raspberry Pi in your closet ❓ 1/4 • Semgrep 0.70+ now supports scanning Terraform source files (HCL) for misconfigurations and security flaws! Announcement: <a href="https://t.co/U1aQxruIfD" target="_blank">r2c.dev/blog/2021/semg…</a> 16 built-in rules: <a href="https://t.co/jny44SkLLl" target="_blank">github.com/returntocorp/s…</a> I will add it to the blog post shortly • Proof <a href="https://twitter.com/QuinnyPig" target="_blank">@QuinnyPig</a> has a favorite and it's <a href="https://twitter.com/AWSIdentity" target="_blank">@AWSIdentity</a>! • 🦫 Meet Ottr: A Serverless Public Key Infrastructure Framework New open source tool by <a href="https://twitter.com/Airbnb" target="_blank">@Airbnb</a> Handles end-to-end certificate rotations without the use of an agent Source code: <a href="https://t.co/W3itx3zG4k" target="_blank">github.com/airbnb/ottr</a> <a href="https://t.co/HGKkKAtlhA" target="_blank">medium.com/airbnb-enginee…</a> • 🤔 pwru: Packet, where are you? <a href="https://twitter.com/ciliumproject" target="_blank">@ciliumproject</a> An eBPF-based tool for tracing network packets in the Linux kernel with advanced filtering capabilities Allows fine-grained introspection of kernel state to facilitate debugging network connectivity issues <a href="https://t.co/NFc7P0vgxs" target="_blank">github.com/cilium/pwru</a> • re:Invent talk is out for editing! A least-privilege journey: IAM policies &amp; Access Analyzer 1⃣1⃣ policy pro-tips 8⃣ full policies 6⃣ pics of Pickles Looking forward to covering fun stuff: conditions, multi-value conditions, cross account, PassRole &amp; everything Access Analyzer • anyway tl;dr here it is. Really keen to hear from folks what I haven't considered. I genuinely can't think of any use cases for IAM users now. <a href="https://t.co/3LYMrDz371" target="_blank">github.com/aidansteele/cl…</a> • Committing my AWS access keys on GitHub just to feel something • "AWS’ temporary event account solution, but the 72 hour expiration policy..." Hold up, AWS provides a mechanism for temporary accounts, but you can only get access to it by hosting remote controlled car competitions?!? • Amazon CloudFront now supports configurable CORS, security, and custom HTTP response headers • Goodbye Microsoft SQL Server, Hello Babelfish • GitHub - pistazie/cdk-dia: Automated diagrams of CDK provisioned infrastructure • Where to start with a mess? • $17,000 bill after support prematurely closed case • Verizon SIMs open their own TCP/IP sessions. And other stuff. • LDAP Password Hunter: Automated tool to lookup for world-readable secrets in LDAP database building a custom list of attributes at runtime based on the CN=Schema,CN=Configuration • Microsoft Defender for Cloud Launches with Support for AWS - Petri.com • Microsoft Expands Security to AWS in Multicloud Push - Dark Reading
8
Monday November, 2021
AWS Security Hub adds support for AWS PrivateLink for private access to Security Hub APIs
Nov 3
AWS Security Huband, nbsp;now supports Amazon Virtual Private Cloud (VPC) endpoints via AWS PrivateLinkand, nbsp;so that you can securely initiate API calls to Security Hub from within your VPC without requiring those calls to traverse across the Internet. AWS PrivateLink support for Security Hub is now available in all AWS …
AWS Secrets Manager increases secrets limit to 500K per account
Nov 2
AWS Secrets Manager now supports a limit of up to 500,000 secrets per account per region, up from 40,000 secrets in the past. This simplifies secrets management for software as a service (SaaS) or platform as a service (PaaS) applications that rely on unique secrets for large numbers of end …
Amazon Chime SDK Meetings - 11 new methods
Nov 4
The Amazon Chime SDK Meetings APIs allow software developers to create meetings and attendees for interactive audio, video, screen and content sharing in custom meeting applications which use the Amazon Chime SDK.
Amazon Connect Service - 5 new methods
Nov 4
This release adds CRUD operation support for Security profile resource in Amazon Connect
Amazon Elastic Compute Cloud - 4 updated methods
Nov 4
This release adds a new instance replacement strategy for EC2 Fleet, Spot Fleet. Now you can select an action to perform when your instance gets a rebalance notification. EC2 Fleet, Spot Fleet can launch a replacement then terminate the instance that received notification after a termination delay
AWS IoT Wireless - 26 new 3 updated methods
Nov 4
Adding APIs for the FUOTA (firmware update over the air) and multicast for LoRaWAN devices and APIs to support event notification opt-in feature for Sidewalk related events. A few existing APIs need to be modified for this new feature.
Implement OAuth 2.0 device grant flow by using Amazon Cognito and AWS Lambda
Jeff LombardoNov 2
In this blog post, you’ll learn how to implement the OAuth 2.0 device authorization grant flow for Amazon Cognito by using AWS Lambda and Amazon DynamoDB. When you implement the OAuth 2.0 authorization framework (RFC 6749) for internet-connected devices with limited input capabilities or that lack a user-friendly browser—such as …
The Five Ws episode 2: Data Classification whitepaper
Jana KayNov 1
AWS whitepapers are a great way to expand your knowledge of the cloud. Authored by Amazon Web Services (AWS) and the AWS community, they provide in-depth content that often addresses specific customer situations. We’re featuring some of our whitepapers in a new video series, The Five Ws. These short videos …
securityhub: 5 new actions, 1 new resource
Nov 6
5 new actions: CreateFindingAggregator (create a finding aggregator, which contains the cross-region finding aggregation configuration), DeleteFindingAggregator (delete a finding aggregator, which disables finding aggregation across regions), GetFindingAggregator (retrieve details for a finding aggregator, which configures finding aggregation across regions), ListFindingAggregators (retrieve a list of finding aggregators, which contain the cross-region …
servicequotas: 1 updated condition
Nov 6
1 updated condition: servicequotas:service (type)
iotwireless: 26 new actions, 2 new resources
Nov 6
26 new actions: AssociateMulticastGroupWithFuotaTask (associate the multicastgroup with fuotatask), AssociateWirelessDeviceWithFuotaTask (associate the wireless device with fuotatask), AssociateWirelessDeviceWithMulticastGroup (associate the wirelessdevice with multicastgroup), CancelMulticastGroupSession (cancel the multicastgroup session), CreateFuotaTask (create a fuotatask resource), CreateMulticastGroup (create a multicastgroup resource), DeleteFuotaTask (delete the fuotatask), DeleteMulticastGroup (delete the multicastgroup), DisassociateMulticastGroupFromFuotaTask (disassociate the multicastgroup from …
0xdabbad00
Scott Piper @0xdabbad00

No more making Lambda@Edge functions just to add HTTP headers to CloudFront.
github.com/aws/aws-sdk-go…

__steele
Aidan W Steele @__steele

I think there's no need for AWS IAM users today. So I made a PoC to "prove" it. First here are the general use-cases for creds

* AWS SSO works great for humans 👍

* Roles work fine inside AWS 👍

* Federation works fine from other clouds 👍

* Raspberry Pi in your closet ❓
1/4

christophetd
Christophe @christophetd

Semgrep 0.70+ now supports scanning Terraform source files (HCL) for misconfigurations and security flaws!

Announcement: r2c.dev/blog/2021/semg…

16 built-in rules: github.com/returntocorp/s…

I will add it to the blog post shortly

christophetd
Christophe @christophetd

Just blogged: Shifting Cloud Security Left — Scanning Infrastructure as Code for Security Issues

Includes a comparison of Terraform static analysis tools and tips for integration in CI/CD pipelines!

blog.christophetd.fr/shifting-cloud…

clintgibler
Clint Gibler @clintgibler

🦫 Meet Ottr: A Serverless Public Key Infrastructure Framework

New open source tool by @Airbnb

Handles end-to-end certificate rotations without the use of an agent

Source code:
github.com/airbnb/ottr

medium.com/airbnb-enginee…

clintgibler
Clint Gibler @clintgibler

🤔 pwru: Packet, where are you? @ciliumproject

An eBPF-based tool for tracing network packets in the Linux kernel with advanced filtering capabilities

Allows fine-grained introspection of kernel state to facilitate debugging network connectivity issues

github.com/cilium/pwru

bjohnso5y
Brigid Johnson @bjohnso5y

re:Invent talk is out for editing!
A least-privilege journey: IAM policies & Access Analyzer
1⃣1⃣ policy pro-tips
8⃣ full policies
6⃣ pics of Pickles
Looking forward to covering fun stuff: conditions, multi-value conditions, cross account, PassRole & everything Access Analyzer

__steele
Aidan W Steele @__steele

anyway tl;dr here it is. Really keen to hear from folks what I haven't considered. I genuinely can't think of any use cases for IAM users now.

github.com/aidansteele/cl…

kmcquade3
Kinnaird McQuade💥🌩 @kmcquade3

Committing my AWS access keys on GitHub just to feel something

0xdabbad00
Scott Piper @0xdabbad00

"AWS’ temporary event account solution, but the 72 hour expiration policy..." Hold up, AWS provides a mechanism for temporary accounts, but you can only get access to it by hosting remote controlled car competitions?!?

awswhatsnew
What’s New on AWS @awswhatsnew

AWS DeepRacer introduces multi-user account management

With a multi-user account set up, organizers (aka Account Administrators) can now provide racers access to the AWS DeepRacer service under their account ID, monitor spending on training and sto... aws.amazon.com/about-aws/what…

Where to start with a mess?

I recently started at an org that exploded in growth over a short time, and was presented with an unusual (and unexpected) ... "challenge."

  • There is only one AWS account in the organization, and it is the management account. Everything, dev, staging, prod, is deployed in this account.
  • 300+ IAM …
$17,000 bill after support prematurely closed case

Hey everyone, I've been dealing with this situation for 2 weeks now and would appreciate any advice on how to handle this. On Oct 21, my account was hacked and AWS Support granted the intruder access to remove service limits on the account, even though this person was from Japan …

buymeacoffee