Advertisement
Guest User

Amazon Cookie Reuse

a guest
Aug 2nd, 2013
1,316
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.98 KB | None | 0 0
  1. Date: Tue, 16 Apr 2013 10:11:36 -0400
  2. Subject: Re: Cookie Invalidation Problem
  3. From: AWS Security <aws-security@amazon.com>
  4. Sender: "Jackson, Matthew" <mjack@amazon.com>
  5. To: Craig Young
  6. CC: AWS Security <aws-security@amazon.com>
  7. Message-ID: <CD92D25E.16782%mjack@amazon.com>
  8. Thread-Topic: Cookie Invalidation Problem
  9. In-Reply-To: <CD8C2A33.15D8B%mjack@amazon.com>
  10. MIME-Version: 1.0
  11. Content-Type: multipart/alternative; boundary="B_3448951899_14425343"
  12.  
  13. --B_3448951899_14425343
  14. Content-Type: text/plain; charset="US-ASCII"
  15. Content-Transfer-Encoding: 7bit
  16.  
  17. Hi Craig,
  18.  
  19. Thank you for reporting this issue to the Amazon Web Services (AWS) Security
  20. Group. We take all reports of security issues seriously and thank you for
  21. sending it to us. Our investigation shows that this is currently working as
  22. designed however we are always looking for new opportunities to serve our
  23. customers better.
  24.  
  25. Please note that the data stored in AWS's authentication cookies are not
  26. valid indefinitely (regardless of the expiration date on the HTTP Cookie
  27. header), and therefore captured cookies do not allow permanent access to
  28. customer accounts. Further, if malware compromises a browser being used to
  29. access the AWS Management Console, it can already surreptitiously perform
  30. actions under the customer's identity and can block the logout function. The
  31. ability to steal limited-lifetime authentication cookies does not present a
  32. particularly greater attack surface.
  33.  
  34. We encourage customers concerned about the locations used for administrative
  35. access to AWS to use IAM users configured with least privilege, and to
  36. optionally restrict the source IP address from which those users can
  37. interact with AWS. This would further mitigate the risk of an authentication
  38. cookie being stolen from a customer browser and used from a different
  39. location.
  40.  
  41. We hope this addresses your reported issue, and thank you again for
  42. contacting AWS Security!
  43.  
  44. Sincerely,
  45. Matt
  46. AWS Security
  47. https://aws.amazon.com/security
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement