Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Imperva Security Update (imperva.com)
4 points by snug on Oct 10, 2019 | hide | past | favorite | 2 comments


> Some key decisions made during the AWS evaluation process, taken together, allowed information to be exfiltrated from a database snapshot. These were: (1) we created a database snapshot for testing; (2) an internal compute instance that we created was accessible from the outside world and it contained an AWS API key; (3) this compute instance was compromised and the AWS API key was stolen; and (4) the AWS API key was used to access the snapshot.


This is why DLP and access controls are so important. Its a total noob mistake, especially for a security company.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: