SRE Weekly Issue #346 • [tl;dr sec] #157 - Transforming Security Champions, Production-ready Osquery • Amazon MemoryDB - 10 updated methods • Amazon SageMaker Service - 7 updated methods • AWS IoT SiteWise - 2 new 4 updated methods • AWS S3 Control - 2 updated methods • OpenSSL Security Advisories - November 2022 • How to use trust policies with IAM roles • Use Amazon Inspector to manage your build and deploy pipelines for containerized applications • See yourself in cyber: Highlights from Cybersecurity Awareness Month • How to control non-HTTP and non-HTTPS traffic to a DNS domain with AWS Network Firewall and AWS Lambda • redshift: 1 new action • route53-recovery-readiness: 1 updated condition • qldb: 1 new action • The OpenSSL punycode vulnerability (CVE-2022-3602): Overview, detection, exploitation, and remediation | Datadog Security Labs • r2c - CVE Analyst • I won’t be attending re:invent after all. 🙁 Nor have I done a good job of responding to DMs or following up on commitments for ages. I’ve been having an extremely bad time this year and I am checking into a psych hospital and changing meds. So hopefully 2023 will be better. • the speed with which he went from "legalize comedy" to "i will literally ban everyone that i think is making fun of me" is just outstanding • My colleagues have released a post and in-depth exploitation walk-through of the OpenSSL vulnerability: <a href="https://t.co/Idu6Lng003" target="_blank">securitylabs.datadoghq.com/articles/opens…</a> tldr • It was downgraded from critical to high • It's exploitable for DoS on Windows, probably not RCE • It's likely not exploitable on Linux at all • I have no idea if publishing this is a good idea. But I think it’s important to normalise bipolar disorder, even the ugly bits. I think my career will be okay and I hope that people won’t treat me differently from now on. • Every time I open this site • Dropped off my ballot today for my first vote in a US general election. Please do vote, it really matters! 🇺🇸 • Maybe we should leave our thoughts and hot takes in a file called .plan in our home directory? • 🗒️ awesome-cybersecurity-conferences A list of a number of security conferences around the world and a link to their videos and slides By <a href="https://twitter.com/Eliyahu_Tal_" target="_blank">@Eliyahu_Tal_</a> <a href="https://t.co/CyLYtBUKFG" target="_blank">github.com/TalEliyahu/awe…</a> • New on Hacking the Cloud - AWS Organizations Defaults: A short post on the default behavior of AWS Organizations and how compromising the management account can lead to the compromise of the entire organization. <a href="https://t.co/csNZ1be2Jw" target="_blank">hackingthe.cloud/aws/general-kn…</a> • 🗒️ <a href="https://twitter.com/owasp" target="_blank">@owasp</a> Software Component Verification Standard (SCVS) Overview by Chris Hughes on the 3 levels of maturity across 6 control categories * Inventory * SBOM * Build Environment * Package Management * Component Analysis * Pedigree and Provenance <a href="https://t.co/Caz7H0Vdwj" target="_blank">blog.aquia.us/blog/2022-09-2…</a> • Amazon AWS Certifications Courses Worth Thousands of Dollars are available FREE on Amazon Store. • Minor rant: NoSQL is not a drop-in replacement for SQL • Who's Going to Re:Invent • Amazon EC2 enables you to opt out of directly shared Amazon Machine Images • Deloitte and AWS partner for latest major entry into BaaS - Insider Intelligence • Credera Becomes AWS Security Competency Partner - PR Newswire

ASD Logo

7
Monday November, 2022

Sponsor

On-Demand: Identity-Based Data Security on AWS

Easily control who can provision and access your critical AWS resources while improving security and compliance with Teleport for AWS.

  • Secure your growing AWS infrastructure
  • Meet security and compliance regulations through complete visibility
  • Increase developer productivity while saving time and money

Watch Now

In a nutshell

My thoughts on the Twitter takeover: You can be the richest man in the world, and have market-disrupting companies, if your management isn't based on goodwill, empathy, or morality it has no value or merit.

A little thought for our colleagues and friends at Twitter. Such a way of doing things would be unthinkable in France or the EU thanks to labor law.

I'm sharing this spreadsheet of tweeps if you have open positions for them.

Amazon MemoryDB - 10 updated methods
Nov 3
Adding support for r6gd instances for MemoryDB Redis with data tiering. In a cluster with data tiering enabled, when available memory capacity is exhausted, the least recently used data is automatically tiered to solid state drives for cost-effective capacity scaling with minimal performance impact.
Amazon SageMaker Service - 7 updated methods
Nov 3
Amazon SageMaker now supports running training jobs on ml.trn1 instance types.
AWS IoT SiteWise - 2 new 4 updated methods
Nov 2
This release adds the ListAssetModelProperties and ListAssetProperties APIs. You can list all properties that belong to a single asset model or asset using these two new APIs.
AWS S3 Control - 2 updated methods
Nov 2
S3 on Outposts launches support for Lifecycle configuration for Outposts buckets. With S3 Lifecycle configuration, you can mange objects so they are stored cost effectively. You can manage objects using size-based rules and specify how many noncurrent versions bucket will retain.
OpenSSL Security Advisories - November 2022
aws@amazon.comNov 1

Initial Publication Date: 2022/11/01 09:00 PDT

AWS is aware of the recently reported issues regarding OpenSSL 3.0 (CVE-2022-3602 and CVE-2022-3786). AWS services are not affected, and no customer action is required. Additionally, Amazon Linux 1 and Amazon Linux 2 do not ship with OpenSSL 3.0 and are not affected by …

How to use trust policies with IAM roles
Jonathan JenkynNov 3
November 3, 2022: We updated this post to fix some syntax errors in the policy statements and to add additional use cases. August 30, 2021: This post is currently being updated. We will post another note when it’s complete. AWS Identity and Access Management (IAM) roles are a significant component …
Use Amazon Inspector to manage your build and deploy pipelines for containerized applications
Scott WardNov 3
Amazon Inspector is an automated vulnerability management service that continually scans Amazon Web Services (AWS) workloads for software vulnerabilities and unintended network exposure. Amazon Inspector currently supports vulnerability reporting for Amazon Elastic Compute Cloud (Amazon EC2) instances and container images stored in Amazon Elastic Container Registry (Amazon ECR). With the …
See yourself in cyber: Highlights from Cybersecurity Awareness Month
CJ MosesNov 2
As Cybersecurity Awareness Month comes to a close, we want to share some of the work we’ve done and made available to you throughout October. Over the last four weeks, we have shared insights and resources aligned with this year’s theme—”See Yourself in Cyber”—to help advance awareness training, and inspire …
How to control non-HTTP and non-HTTPS traffic to a DNS domain with AWS Network Firewall and AWS Lambda
Tyler ApplebaumNov 2
Security and network administrators can control outbound access from a virtual private cloud (VPC) to specific destinations by using a service like AWS Network Firewall. You can use stateful rule groups to control outbound access to domains for HTTP and HTTPS by default in Network Firewall. In this post, we’ll …
redshift: 1 new action
Nov 5
1 new action: GetClusterCredentialsWithIAM (Grants permission to get enhanced temporary credentials to access an Amazon Redshift database by the specified AWS account)
route53-recovery-readiness: 1 updated condition
Nov 5
1 updated condition: aws:TagKeys (type)
qldb: 1 new action
Nov 5
1 new action: PartiQLRedact (Grants permission to redact historic revisions)
__steele
Aidan W Steele @__steele

I won’t be attending re:invent after all. 🙁

Nor have I done a good job of responding to DMs or following up on commitments for ages.

I’ve been having an extremely bad time this year and I am checking into a psych hospital and changing meds. So hopefully 2023 will be better.

2Nov 01 · 5:18 AM
abbyfuller
Abby Fuller @abbyfuller

the speed with which he went from "legalize comedy" to "i will literally ban everyone that i think is making fun of me" is just outstanding

43Nov 07 · 2:32 AM
christophetd
Christophe Tafani-Dereeper @christophetd

My colleagues have released a post and in-depth exploitation walk-through of the OpenSSL vulnerability: securitylabs.datadoghq.com/articles/opens…

tldr
• It was downgraded from critical to high
• It's exploitable for DoS on Windows, probably not RCE
• It's likely not exploitable on Linux at all

121Nov 01 · 5:51 PM
__steele
Aidan W Steele @__steele

I have no idea if publishing this is a good idea. But I think it’s important to normalise bipolar disorder, even the ugly bits.

I think my career will be okay and I hope that people won’t treat me differently from now on.

1Nov 01 · 5:18 AM
colmmacc
Colm MacCárthaigh @colmmacc

Dropped off my ballot today for my first vote in a US general election. Please do vote, it really matters! 🇺🇸

5Nov 06 · 4:32 AM
colmmacc
Colm MacCárthaigh @colmmacc

Maybe we should leave our thoughts and hot takes in a file called .plan in our home directory?

7Nov 04 · 9:17 PM
clintgibler
Clint Gibler @clintgibler

🗒️ awesome-cybersecurity-conferences

A list of a number of security conferences around the world and a link to their videos and slides

By @Eliyahu_Tal_

github.com/TalEliyahu/awe…

26Nov 02 · 6:00 PM
Frichette_n
Nick Frichette - @frichetten@fosstodon.org @Frichette_n

New on Hacking the Cloud - AWS Organizations Defaults: A short post on the default behavior of AWS Organizations and how compromising the management account can lead to the compromise of the entire organization. hackingthe.cloud/aws/general-kn…

20Nov 05 · 1:17 AM
clintgibler
Clint Gibler @clintgibler

🗒️ @owasp Software Component Verification Standard (SCVS)

Overview by Chris Hughes on the 3 levels of maturity across 6 control categories

* Inventory
* SBOM
* Build Environment
* Package Management
* Component Analysis
* Pedigree and Provenance

blog.aquia.us/blog/2022-09-2…

17Nov 01 · 1:00 AM
Minor rant: NoSQL is not a drop-in replacement for SQL

Could be obvious, could be not but I think this needs to be said.

Once in a while I see people recommend DynamoDb when someone is asking how to optimize costs in RDS (because Ddb has nice free tier, etc.) like it's a drop-in replacement -- it is not. It's …

Who's Going to Re:Invent

Really looking forward to it