Securing AWS Credentials on Engineer's Machines
99designs.com
99designs.com
I suppose we need to clearly define the attack vector that we are trying to prevent. If we define the attack vector to be a MTP using developer credentials to obtain access to the production environment for any amount of time, then does aws-vault address that use-case?
If the long lived credentials on the developer box only have permission to request short lived creds from STS which have greater permissions, then I understand how that is certainly better than the MTP having long lived creds with greater permissions. But, how much better is it really? If the creds have IAM permissions, then the MTP could use the temporary creds to lock everyone else out except the root account.
I suppose the article is trying to make the point that the short lived credentials need to have appropriate permissions for the task which the developer needs to complete on a regular basis? Even so, someone somewhere needs to have creds which can modify IAM so that we can manage users, right?
I feel like I am talking myself into a rabbit hole here. Can anyone pull me out? I think/hope that I am missing something obvious and I'm hoping that the answer is "we're not solving everything, but we are reducing the attack surface".
Thoughts?
AWS offers the concept of Power Users, which have access to everything except IAM. We use them for most things, which mitigates the risk of an attacker escalating temporary access into long term access. They can still cause a lot of damage, but it's time limited.
I would love to see more work on the AWS side to address this with integration to keychain, 1password and the like.