154 points by uvuv 3 days ago | 35 comments | View on ycombinator
chuckadams 2 days ago |
btown 2 days ago |
From everything I know about pentesting, they should have stopped before doing this, right? From https://hackerone.com/aws_vdp?type=team :
> You may only interact with accounts you own or with explicit written permission from AWS or the account owner
mikesurowiec 2 days ago |
Glad to see a few more security knobs on actions these days!
themafia 2 days ago |
This article lends some credibility to that notion.
tnkuehne 2 days ago |
jacquesm 2 days ago |
teeklp 2 days ago |
McAdam 2 days ago |
Said tokens didn't have admin access, but had enough privileges to invite other users to become full admins. Not sure if they were rotated, but github tokens are usually long-lived, like up to a year. Hey, isn't AWS the one always lecturing us to use temporary credentials? To be fair, AWS did more than just fix the regex, they introduced an "approve workflow run" UI unto the PR process that I think GH is also using now (not sure about that).