Episode Summary
Episode Show Notes & Transcript
- Cost of a Data Breach Report: https://securityintelligence.com/cost-of-data-breach-bottom-line/
- Got its ass handed to it in a security breach last week: https://threatpost.com/Godaddys-latest-breach-customers/176530/
- Millions of Brazilians: https://www.zdnet.com/article/millions-of-brazilians-exposed-in-wi-fi-management-software-firm-leak/
- âYou can now securely connect to your Amazon MSK clusters over the internetâ: https://aws.amazon.com/about-aws/whats-new/2021/11/securely-connect-amazon-msk-clusters-over-internet/
- âAWS Security Profiles: Megan OâNeil, Sr. Security Solutions Architectâ: https://aws.amazon.com/blogs/security/aws-security-profiles-megan-oneil-sr-security-solutions-architect/
- AWS Security Profiles: Merritt Baer, Principal in OCISO: https://aws.amazon.com/blogs/security/aws-security-profiles-merritt-baer-principal-in-ociso/
- Super important things to know: https://github.com/SummitRoute/aws_breaking_changes/issues/56
- Permissions.cloud: https://aws.permissions.cloud/
IBM put out its annual Cost of a Data Breach Report which is interesting, but personally I find it genius. This is how you pollute SEO for the
search term âIBM Data Breachâ, which is surely just a matter of time if it hasnât already happened.
Speaking of, GoDaddy effectively got its ass handed to it in a security breach last week. We found out of course via an SEC filing instead of GoDaddy doing the smart thing and proactively getting in front of it. Apparently they were breached for at least two-and-a-half months, nobody noticed, and 1.2 million people got their admin creds stolen. I canât stress enough that you should not be doing business with
GoDaddy.
âAWS Security Profiles: Megan OâNeil, Sr. Security Solutions Architect.â I really dig these! The problem is that the AWS security blog only really seems to put these out around major AWS conferences when thereâs a bunch of other announcements. Iâd love it if more of the AWS blogs would do periodic âThe faces, voices, and people that power AWSâ profiles because I assure you, most of the people building the magic never take the stage at these conferences.
And thatâs what happened in AWS security. Thank you for listening. Iâll talk to you next week if I survive re:Invent.
Corey: Thank you for listening to the AWS Morning Brief: Security Edition with the latest in AWS security that actually matters. Please follow
AWS Morning Brief on Apple Podcast, Spotify, Overcastâor wherever the hell it is you find the dulcet tones of my voiceâand be sure to sign up for the Last Week in AWS newsletter at lastweekinaws.com.
Transcript
Links:
* Cost of a Data Breach Report: https://securityintelligence.com/cost-of-data-breach-bottom-line/
* Got its ass handed to it in a security breach last week: https://threatpost.com/Godaddys-latest-breach-customers/176530/
* Millions of Brazilians: https://www.zdnet.com/article/millions-of-brazilians-exposed-in-wi-fi-management-software-firm-leak/
* âYou can now securely connect to your Amazon MSK clusters over the internetâ: https://aws.amazon.com/about-aws/whats-new/2021/11/securely-connect-amazon-msk-clusters-over-internet/
* âAWS Security Profiles: Megan OâNeil, Sr. Security Solutions Architectâ: https://aws.amazon.com/blogs/security/aws-security-profiles-megan-oneil-sr-security-solutions-architect/
* AWS Security Profiles: Merritt Baer, Principal in OCISO: https://aws.amazon.com/blogs/security/aws-security-profiles-merritt-baer-principal-in-ociso/
* Super important things to know: https://github.com/SummitRoute/aws_breaking_changes/issues/56
* Permissions.cloud: https://aws.permissions.cloud/
Transcript
Corey: This is the AWS Morning Brief: Security Edition. AWS is fond of saying security is job zero. That means itâs nobody in particularâs job, which means it falls to the rest of us. Just the news you need to know, none of the fluff.
Corey: This episode is sponsored in part by LaunchDarkly. Take a look at what it takes to get your code into production. Iâm going to just guess that itâs awful because itâs always awful. No one loves their deployment process. What if launching new features didnât require you to do a full-on code and possibly infrastructure deploy? What if you could test on a small subset of users and then roll it back immediately if results arenât what you expect? LaunchDarkly does exactly this. To learn more, visit launchdarkly.com and tell them Corey sent you, and watch for the wince.
Corey: âSecurity is Job Zeroâ according to AWS. Next week Iâll have a fair bit on that I suspect, since this week is re:Invent. Letâs see what happened before the storm hit.
IBM put out its annual Cost of a Data Breach Report which is interesting, but personally I find it genius. This is how you pollute SEO for the search term âIBM Data Breachâ, which is surely just a matter of time if it hasnât already happened.
Speaking of, GoDaddy effectively got its ass handed to it in a security breach last week. We found out of course via an SEC filing instead of GoDaddy doing the smart thing and proactively getting in front of it. Apparently they were breached for at least two-and-a-half months, nobody noticed, and 1.2 million people got their admin creds stolen. I canât stress enough that you should not be doing business with GoDaddy.
And to complete the trifecta, âMillions of Braziliansâ is a fun thing to say unless youâre talking about whoâs been victimized by an S3 Bucket Negligence Award; then nobodyâs having fun at all.
The AWS security blog had a few things to say. âYou can now securely connect to your Amazon MSK clusters over the internet.â Wait, what? What the hell was going on before? Were you unable to access the clusters over the internet, or were you able to do so but it was insecurely? This is terrifying framing.
âAWS Security Profiles: Megan OâNeil, Sr. Security Solutions Architect.â I really dig these! The problem is that the AWS security blog only really seems to put these out around major AWS conferences when thereâs a bunch of other announcements. Iâd love it if more of the AWS blogs would do periodic âThe faces, voices, and people that power AWSâ profiles because I assure you, most of the people building the magic never take the stage at these conferences.
There was another profile of Merritt Baer. Who is a principal in the office of the CISO, and sheâs an absolute delight. One of these days, post-pandemic, weâre going to try and record some kind of video or other, just so we can name it âQuinn and Baer it.â
Corey: This episode is sponsored in part by something new. Cloud Academy is a training platform built on two primary goals: having the highest quality content in tech and cloud skills, and building a good community that is rich and full of IT and engineering professionals. You wouldnât think those things go together, but sometimes they do. Itâs both useful for individuals and large enterprises, but hereâs what makes this something newâI donât use that term lightlyâCloud Academy invites you to showcase just how good your AWS skills are. For the next four weeks, youâll have a chance to prove yourself. Compete in four unique lab challenges where theyâll be awarding more than $2,000 in cash and prizes. Iâm not kidding: first place is a thousand bucks. Pre-register for the first challenge now, one that I picked out myself on Amazon SNS image resizing, by visiting cloudacademy.com/coreyâC-O-R-E-Y. Thatâs cloudacademy.com/corey. Weâre going to have some fun with this one.
Corey: And of course, âMacie Classic alerts that derive from AWS CloudTrail global service events for AWS Identity and Access Management (IAM) and AWS Security Token Service (STS) API calls will be retired (no longer generated) in the us-west-2 (Oregon) AWS Region.â See, thatâs one of those super important things to know, and I hate how AWS buries it. That said, donât use Macie Classic because it is horrifyingly expensive compared to modern Macie.
And from the tools and tricks area, I discovered permissions.cloud last week and itâs great. The website uses a variety of information gathered within the IAM dataset and then exposes that information in a clean, easy-to-read format. Itâs there to provide an alternate community-driven source of truth for AWS identity. Itâs gorgeous as well, so you know itâs not an official AWS product.
And thatâs what happened in AWS security. Thank you for listening. Iâll talk to you next week if I survive re:Invent.
Corey: Thank you for listening to the AWS Morning Brief: Security Edition with the latest in AWS security that actually matters. Please follow AWS Morning Brief on Apple Podcast, Spotify, Overcastâor wherever the hell it is you find the dulcet tones of my voiceâand be sure to sign up for the Last Week in AWS newsletter at lastweekinaws.com.
Announcer: This has been a HumblePod production. Stay humble.

