c/blueteamsec · by digicat@infosec.pub · 19d768 Leaked Corporate AWS Keys Held Full Admin Rights https://trufflesecurity.com/blog/leaked-corporate-aws-keys-held-full-admin-rights29 points · 2 comments · view on lemmy.world
2 Comments
zwerg@feddit.org · 4 pts · 19d
Why the fuck would you create keys for the root of your AWS accounts? Also, best practice is to not have any key live longer than 1 hour. So much is wrong here...
Sprocketfree@sh.itjust.works · 1 pts · 19d
Really don't use keys at all. OIDC really helps fix this.