Cloud Security
Corey Quinn Says AWS's Leaked-Key Quarantine Leaves Attackers Too Much Room
AWS attaches a quarantine policy to keys it detects as leaked, but Corey Quinn argues in The Register that the deny-list still lets an attacker assume other roles, destroy audit logs, read secrets, and lock storage. Treat a leaked key as a full compromise.