A cross-account database vulnerability in Azure PostgreSQL
wiz.io
wiz.io
Caused by a bad regexp in the authentication mechanism acting as the first security layer, and lack of network-level inter-tenant isolation as a second layer of security.
Kind of ironic that his new security startup uncovers his failings at his old job...
[0] https://en.globes.co.il/en/article-microsoft-names-assaf-rap...
AWS isn't perfect, but you really don't see many exploits on this scale. What is Microsoft doing wrong here?
That blog post also highlights that AWS may have a tendency to sweep security issues under the rug if there is no customer impact.
Either way, we migrated to Flexible Server on day one of GA purely for the performance benefits (Linux) over Single Server (Windows). While there has been some painful moments, also around High Availability, the service has been a huge leap forward.