Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

The Unmask IAM Permission: API Gateway Access Logging

Summary

Bishop Fox explains that AWS API Gateway access logs aren't encrypted by default and are readable with the right IAM permission, then shows how data protection policies can mask secrets like AWS keys.
Published
Collected

original ↗

Related coverage

back