← All talks

Secure AWS: Stop Secret Theft & Data Center Fires! #shorts

BSides Frankfurt0:32779 viewsPublished 2026-04Watch on YouTube ↗
About this talk
Prevent AWS secrets theft by separating accounts. Your auto-scaling account shouldn't delete backups, and your backup account shouldn't delete resources. Keep identities separate and avoid storing all secrets in one script. #AWS #Cybersecurity #DataCenter #CloudSecurity #DevOps
Show transcript [en]

How do you prevent this from, you know, how do you prevent somebody stealing an AWS secret and burning down your entire data center? Well, don't have one account to rule them all. Uh your accounts should be separated. Your account that does your auto scaling up and down shouldn't also be able to delete all of your backups. Your account that does your backups, maybe it can do backups, but it can't delete the resources. You know, things like that. Separate these out, keep them you know, keep these identities separate. And don't store all your secrets in one script, you know.