Thanks to everyone who attended my #fwdcloudsec talk 🙏
Slides and videos should be up at the end of the week if you missed it.
Links:
https://t.co/2KaOqbn8UC
https://t.co/jG77E3kExz
https://t.co/EHeTGoFOMT
https://t.co/dvY0xa6ziQ
Just watched Jared Naude's talk at @fwdcloudsec . Glad to see he's had some success expanding the shared responsibility model to separate app and infrastructure/platform teams in his work. May be the inspiration I need to help drive this ahead at my company.
🍪IAM Access Analyzer has a new treat for all you permission setters out there in #AWS land.🍪Now, Access Analyzer generates policies based on your CloudTrail activity. (1/11)
https://t.co/TZNzFSxOZ2
@zoph > ReadOnlyAccess exceed the size limit with 15745 characters. Did they made an exception for this use-case?
Wow, I was wondering how teams set up full read access with IAM limitations. And that policy sometimes doesn't even have what I need. 😆
@peterskillman If I know the identifier for a resource in my account but don't know what region it's in, there should be a way for me to look it up without checking in every region.
How'd I miss this? The #AWS#SystemsManager docs were updated earlier this month to recommend policies which do *not* include R/W access to all S3 buckets in the account. Thank you! https://t.co/NDuiccPwap
I know AWS IAM much more deeply than most people who work with AWS can be expected to know it, but wow it gets complicated. Anything AWS can provide to make this easier would be greatly appreciated. Love these ideas!
For service roles, remove s3:ListAllMyBuckets and similar List/Describe privs. Code normally knows what buckets it needs to work with, and does not need to list them.
Hi #awswishlist - Please bring out tag-based access controls for KMS soon. The only supported access control on the IAM side requires the generated identifier for the KMS key, which I don't know in advance.
In part 2 of our AWS privilege escalation series, we discuss 3 new IAM privilege escalation methods abusing Lambda Layers and SageMaker Jupyter Notebooks. https://t.co/DCJJpK2M0C
DX is one of the few services for which I don't have a use case for this granularity, but I like the increased consistency. What's even better is that the IAM docs are already updated. Thank you, #AWS! 🙏 https://t.co/qzyhLrsbkA
AWS Direct Connect Now Supports Resource Based Authorization, Tag Based Authorization, and Tag on Resource Creation
AWS Direct Connect is a cloud service solution that makes it easy to establish a dedicated network connection from your premises to ... https://t.co/57COul25nE
I’ve seen a few people ask about the process of building an integration with Amazon EventBridge as a SaaS provider. We’re working on getting some additional, more official materials published, but in the meantime here’s a thread on the technical bits of the process. 1/12
@0xdabbad00 As for me, I'm very OK with announcements spaced out instead of a barrage. Something to dig into during boring parts of the keynote, and there will always be boring parts.
"EventBridge Rules" is way too descriptive and makes me visualize it. I'm seeing a big party taking place at a bridge and folks yelling "Eventbridge rules!". But the dawn reveals that someone has spraypainted on the bridge "Eventbridge sucks!"
I don't think it was well advertised on release, but Amazon EventBridge is replacing #AWS CloudWatch Events. That is to say, we should now refer to those resources as "EventBridge Rules".