• Alien Nathan Edward@lemm.ee
    link
    fedilink
    English
    arrow-up
    51
    ·
    2 years ago

    I work in a HIPAA-covered industry and if our AWS and GCP buckets are insecure that’s on us. Fuck Amazon, but a hammer isn’t responsible for someone throwing it through a window and a cloud storage bucket isn’t responsible for the owner putting secret shit in it and then enabling public access.

    • zalgotext@sh.itjust.works
      link
      fedilink
      arrow-up
      13
      ·
      2 years ago

      Yeah I hate Amazon as much as the next person, but this is a people/process problem, not an Amazon problem. Amazon doesn’t know or care what you put into an AWS bucket (within reason, data tracking, etc, blah blah blah). People taking classified documents and uploading it to an Internet-connected cloud service is procedurally wrong on so many levels.

        • zalgotext@sh.itjust.works
          link
          fedilink
          arrow-up
          5
          ·
          2 years ago

          No, it literally cannot be both, full stop. There should rigorous, well defined procedures and processes for handling classified data, and chiefly among those should be something along the lines of “don’t upload classified documents to a publicly-available internet-connected location/service/filestore/etc”. If it’s not, a security officer has not done their job.

        • nxdefiant@startrek.website
          link
          fedilink
          arrow-up
          1
          ·
          2 years ago

          The north east US is dotted with high (physical) security Amazon data centers . I promise those aren’t hosting files you can search Google for, if you know what I mean.

    • Dejected Warp Core@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      2 years ago

      What kills me about S3 is that the use cases for publicly accessing S3 contents over HTTP have got to be vanishingly small compared to every other use of the service. I appreciate there’s legacy baggage here but I seriously wonder why Amazon hasn’t retired public S3 and launched a distinct service or control for this that’s harder to screw up.

      • capital@lemmy.world
        link
        fedilink
        arrow-up
        4
        ·
        2 years ago

        Public access is disabled by default and it warns you when you enable it. How much more idiot proof does it need to be?

        • Dejected Warp Core@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          2 years ago

          Honestly, I’m for removing the option and moving that “feature” somewhere else in AWS entirely. And those warnings aren’t really a thing when using IaC. Right now it’s still a “click here for self harm” button, even with the idiot proofing around it.

  • Septimaeus@infosec.pub
    link
    fedilink
    arrow-up
    46
    ·
    2 years ago

    Such examples of OpSec competence make it easy to dismiss the majority of government conspiracy theories IMHO.

    • Maggoty@lemmy.world
      link
      fedilink
      arrow-up
      10
      ·
      2 years ago

      I go back to the veteran comedian every time.

      We can’t even stop our privates from telling their stripper girlfriend about the mission they’re going on the next day, and people think there’s a giant conspiracy out there where nobody talks…

      Then there’s the Warrantless Wiretap program under the Bush Administration. Cheney kept the authorization memo in his personal lawyer’s safe. Only 7 people knew it existed. Shit still leaked.

      • Septimaeus@infosec.pub
        link
        fedilink
        arrow-up
        5
        ·
        2 years ago

        Only 7. That’s perfect. I forget who said “three may keep a secret if two are dead” but of all the mustache twirling pricks in that admin, Cheney should have known.

        Edit: it’s Ben Franklin’s joke, apparently. I doubt he’d mind.

  • Dizzy Devil Ducky@lemm.ee
    link
    fedilink
    English
    arrow-up
    23
    arrow-down
    4
    ·
    2 years ago

    Okay, the question I have, is why any government from a developed country would ever use something like AWS or something that everyone can obtain access to rather than making their own private solutions to these problems?

    • hackerwacker@lemmy.ml
      link
      fedilink
      arrow-up
      37
      ·
      2 years ago

      It’s easier to hire someone who knows aws than to train someone on your custom thing. I don’t really agree, but that’s mostly the reasoning.

      • JDubbleu@programming.dev
        link
        fedilink
        arrow-up
        5
        ·
        2 years ago

        Not to mention in house solutions are basically guaranteed to cost more than AWS to get something even close to as comparable. A basic service like Lambda is complex as fuck and has had billions of dollars poured into making it what it is today.

    • psmgx@lemmy.world
      link
      fedilink
      arrow-up
      5
      ·
      2 years ago

      Cloud presents several advantages,and GovCloud is a thing.

      Like, Amazon has SCIF cloud offerings. These leaks were cuz some dumbass contractor exposed a repo to the internet

    • lemmyreader@lemmy.mlOP
      link
      fedilink
      English
      arrow-up
      5
      ·
      2 years ago

      Another question could be : which developed country is not yet using the popular AWS already and why ?

      For example : https://press.aboutamazon.com/2023/10/amazon-web-services-to-launch-aws-european-sovereign-cloud

      Customers, AWS Partners, and regulators welcoming the new AWS European Sovereign Cloud include the German Federal Office for Information Security (BSI), German Federal Ministry of the Interior and Community (BMI), German Federal Ministry for Digital and Transport, Finland Ministry of Finance, National Cyber and Information Security Agency (NÚKIB) in the Czech Republic, National Cyber Security Directorate of Romania, SAP, Dedalus, Deutsche Telekom, O2 Telefónica in Germany, Heidelberger Druckmaschinen AG, Raisin, Scalable Capital, de Volksbank, Telia Company, Accenture, AlmavivA, Deloitte, Eviden, Materna, and msg group

    • golden_zealot@lemmy.ml
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 years ago

      I expect the same reasons they’re mostly all using Microsoft Office, Windows, and Active Directory. Because it’s cheaper than doing it yourself.

    • MetaCubed@lemmy.world
      link
      fedilink
      arrow-up
      4
      ·
      edit-2
      2 years ago

      My bets are on “cloud infrastructure is bad for highly secret information” rather than “public web honeypot with zero obfuscation” Edit: likely fake. The sensationalist in me would love it if this was real because it would confirm my “cloud storage bad” biases, but alas, the document markings dont appear to be consistent with my understanding of official US Government confidentiality/secrecy markings

      • capital@lemmy.world
        link
        fedilink
        arrow-up
        3
        ·
        2 years ago

        If S3, it’s not cloud storage’s fault some dummies enable public access to buckets which is disabled by default.

        • MetaCubed@lemmy.world
          link
          fedilink
          arrow-up
          3
          ·
          2 years ago

          Youre correct it’s not the provider’s fault, but it’s much harder in my very biased opinion to accidentally expose a secure 100% internal intranet than it is to accidentally put a top secret document in a public data bucket.

          But it’s a moot argument in this case anyway. Fake documents means these are likely exposed just to troll folks like us.

  • nieminen@lemmy.world
    link
    fedilink
    arrow-up
    3
    ·
    2 years ago

    Second result for me was a document about Russian hackers and their demands that we enstate trump as president after he lost.