This podcast covers security topics like data loss in the cloud, leaked IAM keys, user experience with security hub, Google deprecating security offerings, AWS enhancing firewall manager and MFA requirements, torch serve issue, and a tip to patch the Libcurl high severity issue.
Lack of consistent handling of security breaches reveals a lack of formalized process at AWS.
Delayed enhancement of MFA requirements indicates a lack of integral security measures in AWS design process.
Deep dives
Lack of Consistency in Handling IAM Keys
The podcast discusses a concerning incident where Chris Farris intentionally leaked seven IAM keys in public. Despite the SCP blocking access, he received six different responses from AWS. The lack of consistent handling of such security breaches reveals a lack of formalized process at AWS.
Delayed Implementation of MFA Requirements
Another important point highlighted in the podcast is AWS' delayed enhancement of MFA requirements. While many companies already require MFA during onboarding, AWS is only planning to enhance their MFA requirements in 2024. This delay indicates that robust security measures were bolted on rather than being integral to the design process.
Last week in security news: AWS Firewall Manager supports referencing of Security Groups, Secure by Design: AWS to enhance MFA requirements in 2024, You Can't Control Your Data in the Cloud, and more!