couldnt attackers then grab your EC2 dashboard cookie and possibly compromise your EC2 instance ?
I mean if you need to login there first via an unsecure session, its not really that much safer
I mean if you need to login there first via an unsecure session, its not really that much safer