Hacker Newsnew | past | comments | ask | show | jobs | submit | bnchandrapal's commentslogin

TL;DR: Add MFA to AWS root user. If you don't have MFA with root AND your email server of root email is hosted in same AWS account, it gets tricky to recover.

Sidenote, I was shocked to see "There was an AWS keypair saved in the CI secrets that hadn't been used since 2022."


Yes, you're right. Reading my statement in hindsight shows thats not correct. My intention was to convey that you can check for the existence of common IAM users and roles in the accounts (and even existence of company specific entities like users with first.last pattern, product names, etc) I've slightly updated the point a bit.


https://badshah.io/

Blog posts on Cloud Security, DevSecOps and other personal experiments+experiences in security

RSS: https://badshah.io/index.xml


Ahhh. AWS Control tower has not cost but it requires AWS Config to be enabled. Config is yet another AWS service that can get costly over time (if continuous monitoring of changes is enabled)


Out of curiosity, did you have any data lakes on S3? Did you find optimization techniques for the same?


Nope, but did realise we had some open buckets we didn't realise were open. Thankfully we didn't store sensitive information in there despite having 2PB of files in there.


There are a few AWS security services which are free/priced reasonably.

Some free services:

1. AWS Org (Disable services and enforce guardrails)

2. VPC (Create private networks)

3. IAM (User access and IAM policy analyzer to help with least priv)

4. IAM Access Analyzer (Alert on resources with cross account & public access)

5. SSM Inventory & Patch manager (Basic check if all VMs have security updates installed)

Reasonably priced IMO:

1. AWS WAF with free managed rules (when rightly configured you get lesser FP and high ROI)


Those services are gateway, or requirements for using other services though.

A VPC isn't useful without EC2 instances in it. AWS Organizations allows you to create more accounts, with more instances, databases etc in them!


Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: