#awsconsole — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #awsconsole, aggregated by home.social.
-
Supply Chain Vuln Compromised Core AWS GitHub Repos & Threatened the AWS Console
https://www.wiz.io/blog/wiz-research-codebreach-vulnerability-aws-codebuild
#HackerNews #SupplyChainVulnerability #AWS #GitHub #Repos #AWSConsole #CyberSecurity #CloudSecurity
-
Supply Chain Vuln Compromised Core AWS GitHub Repos & Threatened the AWS Console
https://www.wiz.io/blog/wiz-research-codebreach-vulnerability-aws-codebuild
#HackerNews #SupplyChainVulnerability #AWS #GitHub #Repos #AWSConsole #CyberSecurity #CloudSecurity
-
Supply Chain Vuln Compromised Core AWS GitHub Repos & Threatened the AWS Console
https://www.wiz.io/blog/wiz-research-codebreach-vulnerability-aws-codebuild
#HackerNews #SupplyChainVulnerability #AWS #GitHub #Repos #AWSConsole #CyberSecurity #CloudSecurity
-
Supply Chain Vuln Compromised Core AWS GitHub Repos & Threatened the AWS Console
https://www.wiz.io/blog/wiz-research-codebreach-vulnerability-aws-codebuild
#HackerNews #SupplyChainVulnerability #AWS #GitHub #Repos #AWSConsole #CyberSecurity #CloudSecurity
-
Supply Chain Vuln Compromised Core AWS GitHub Repos & Threatened the AWS Console
https://www.wiz.io/blog/wiz-research-codebreach-vulnerability-aws-codebuild
#HackerNews #SupplyChainVulnerability #AWS #GitHub #Repos #AWSConsole #CyberSecurity #CloudSecurity
-
I was stunned when I first saw this diagram and it hasn't changed in the months/years since they rolled it out, but then they never fix anything bsky.app/profile/symb... #aws #awsfail #awsconsole #ux
RE: https://bsky.app/profile/did:plc:osg2vzhifd2tjfsvfwua7scy/post/3kev2qb3lot2w -
TIL, there's a hard coded client_id in the #AWS #awsconsole for what I suspect is an AWS managed account that handles oauth2.0 for root/some login types.
The client_id depending on the service that it first redirects looks like this arn:aws:iam:015428540659:user/s3
Another service that I've noticed is phd-console (Which I think is AWS health dashboard).
So in this pattern it looks like your secret access key is treated as the client secret in an authorization code flow.
The code/access token returned by AWS is an opaque encrypted JWT.
-
Does anyone know if there's a way to turn off this popup in AWS console, or at least keep it from switching tabs automatically? Or can tell me that there's no way to do it so I quit hoping?
#aws #awsconsole #amazon #pathologicalUX #onlyaserialkillerwoulddothisonpurpose