🔦 Highlight of the week
Happy new year! 🎉
📢 MAMIP (Monitor AWS Managed IAM Policies)
Policies changed since last week:
- AWSThinkboxDeadlineResourceTrackerAdminPolicy
- AmazonChimeVoiceConnectorServiceLinkedRolePolicy
- AmazonESCognitoAccess
- AmazonOpenSearchServiceCognitoAccess
- ViewOnlyAccess
Get notified of policy change using this Twitter bot. 🐦
🆕 MASE - Monitor AWS Services and Regional Endpoints on Twitter

The day when the AWS Support got access to your S3 data.
In this thread, you will find details about the security incident that leads to this unattended access for millions of AWS customers. 🧵

AWSSupportServiceRolePolicy just got s3:GetObject. 😱 That role is supposed to only have metadata visibility. @AWSSecurityInfo you need to roll that back.

AWSSupportServiceRolePolicy ... github.com/z0ph/MAMIP/com…

Genie: You have 3 wishes
Me: I wish the status page was updated more often.
Genie: Granted. There will be more outages. What else?
Me: 😱 ... I wish AWS support was more helpful.
Genie: Granted. They have read access to all your data now.
Me: 😱 I'm not doing this anymore. 😭

On the plus side, now there's a specific event to point to when justifying encryption at rest in AWS. Too bad that event was "AWS granted themselves access to all your S3 objects for a few hours."

This has been the shittiest year of my life.
We had to terminate at 15 weeks, during lockdown. The next week the heartless Texas law went into effect. I’ve been overwhelmed by waves of grief. I cry at every baby I see. And now my friend has miscarried at 17 weeks.
😭

As 2021 comes to an end, I compiled a list of cloud security incidents and vulnerabilities that were publicly disclosed this year.
blog.christophetd.fr/cloud-security…
🧵⬇️

Takeaways:
1. IAM is HARD, even AWS is failing.
2. Change made to IAM should always be peer-reviewed, manually, and using linting.
3. Encrypt using your own customer-managed keys

AWSSupportServiceRolePolicy ... github.com/z0ph/MAMIP/com…

I don't know who needs to hear this, but you can tail AWS CloudWatch log groups easily using github.com/lucagrulla/cw. Example:
cw tail /aws/apigateway/rest/myapi/prod --region us-west-1 --follow
And it just ✨works✨
- 🖊️ This newsletter was fwd to you? Subscribe here
- 💌 Want to suggest new content: contact me or reply to this email
- ⚡️ Powered by Mailbrew
- 🐦 Follow me on Twitter or hire me.