768 Leaked Corporate AWS Keys Held Full Admin Rights

https://trufflesecurity.com/blog/leaked-corporate-aws-keys-held-full-admin-rights

29 points · 2 comments · view on lemmy.world

2 Comments

zwerg@feddit.org · 4 pts · 19d

Why the fuck would you create keys for the root of your AWS accounts? Also, best practice is to not have any key live longer than 1 hour. So much is wrong here...

Sprocketfree@sh.itjust.works · 1 pts · 19d

Really don't use keys at all. OIDC really helps fix this.