HN user

dagrz

76 karma
Posts16
Comments22
View on HN

How would you feel if an attacker could read your AWS resource tags? Turns out they can! We’ve found a way to enumerate various metadata from public resources and created a tool to help you test your environment.

Author here.

There's been a lot of great work recently on hacking Github-AWS OIDC integrations but I've think we've undersold how bad it is. Here's my guide to finding all the vulnerable roles in all public repos, including new commits in real time.

For those that aren't aware, it's devastating for anyone affected. You give an AWS role permission to be assumed by Githuab Actions, only you misconfigure it not to match the repo or org name. The result is a classic confused deputy, where any repo in Github can assume your role.

This applies to everything you do which depends on review.

Want a particular job? Put in more effort than everyone else. Create a ‘I want to work for you’ website. Be prepared at the interview. Understand everything about the organisation. Quote its founders.

Want to have your paper accepted? Do a little research about what they are looking for. Contact the reviewers directly and ask for help. Get your article reviewed by people who have been accepted previously.

Want to have your RFQ response win? Read the requirements carefully. Make the reviewers jobs very easy. Address criteria directly and clearly. Ask questions.

I am consistently surprised by how little effort the average person puts in to any reviewed endeavour. It really doesn’t take that much effort to stand out.

Author here - As an information security manager at a large organisation, this scares me. As much as we train our users and put governance structures in place to help them do the right thing, they don't always make the right decisions and we can't expect them to. LinkedIn is encouraging some really poor behaviour here and putting both itself and other organisations at risk.

This is awesome. I don't know much about typography but every time I try to learn something, I give up pretty quickly because of the overwhelming amount of (boring) information. I love how this guide is set out in easy to read and consume chunks that flow well from each other.

Is it me or does the author of this article, and the abusers of the exploits he writes about, land on the wrong side of both the law and common morality?

Surely EA being a "terrible company" has nothing to do with whether it is okay to steal their products? Moreover, just because there was a coding error/oversight, again doesn't mean it is okay to steal their products? If you have a complaint about a company or discover an exploit, surely there are other more ethical channels to pursue the matters?

For the record, I dislike some of EA's conduct as much as the next person.

You are pointing your anger in the wrong direction. The reality is that security is a hard problem, much too hard for Blizzard, much too hard for RSA, much too hard for banks, and much too hard for governments.

Major companies being hacked is not a new phenomenon. What's new is them (a) detecting the hacks and (b) disclosing them. It's unfortunate but true; you should be happy that they are telling you.

[dead] 14 years ago

For the scenerio you mentioned, just having the login/comment submissions work over SSL results in zero added security. In short, this is because of tools such as SSL strip.

A better suggestion would be to have the entire site available of SSL only. Good to see HN'ers taking security seriously though :)

Yeh there way too many lists of 1-5000 email/passwords available on the web. I'm talking thousands if not tens of thousands. It's just too hard to find and add them all. If you find it hard to think about the website as being a comprehensive answer to password problems, think of it as an awareness raiser in the general public. :)

Trust is an issue no doubt and to some extent I wish I had partnered with a big security brand. However, the reality is that you give your email address to various parties all the time, and regardless of how malicious they are, they are rarely secure. Your email is already public, imho.

There are some leaps that normal users won't make, agreed. It's not an easy problem. Either way I believe that raising awareness in non-techie populations is good.

If you have specific suggestions, I would be happy to discuss them.

I would argue that it's not completely useless as the average person re-uses the same password everywhere. Even if you do it across a small number of sites it could easily start a chain reaction.

In fact, I would say that prompting the average person to change some passwords either way, is a good thing.

Its true, a small number of people enter their passwords. The site has been updated with a quick check to prevent such behaviour. Thanks for the feedback.

If we decided to do notifications I would expect users to not re-use passwords from other sites. I would also expect that such a service would require a trusted security brand behind it to work.