back to article AWS 'Bucket Monopoly' attacks could allow complete account takeover

Critical flaws across at least six Amazon Web Services cloud services could have allowed attackers to execute remote code, steal data, or even takeover a user's account without their knowledge, according to research presented today at Black Hat. Aqua Security's Nautilus team detailed the vulnerabilities, which have since been …

  1. Zippy´s Sausage Factory
    FAIL

    Basically, we need obfuscation for cloud bucket names, then? Easy enough to use a GUID in the name when you create it, I suppose, if someone can already predict your bucket name.

    The only difficulty is persuaded corporate management who will say "no, this doesn't fit our corporate naming scheme, you must stick to it with no deviations!" And this is what we get as a result.

    1. martinusher Silver badge

      The hash sounds a bit like a widely known password -- very secure, that!

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like