Amazon Macie Launches (Aug 2017): Machine Learning for Finding Sensitive Data in S3
In August 2017, AWS launched Amazon Macie, a service that used machine learning to discover, classify and protect sensitive data stored in Amazon S3. It...
In August 2017, AWS launched Amazon Macie, a service that used machine learning to discover, classify and protect sensitive data stored in Amazon S3. It...
Amazon Macie scans S3 buckets for sensitive data such as names, financial information and credentials. Here is how to run it effectively without a surprise...
Use this checklist before and after enabling Amazon Macie to get value quickly while keeping costs predictable.
The short version: In 2017, AWS released Macie, a tool that finds sensitive data like customer records hidden in cloud storage. Its premise is simple and...
In July 2017, UpGuard researchers reported that records belonging to millions of Verizon customers were sitting in a publicly accessible Amazon S3 bucket....
Bucket policies decide who can access data in Amazon S3. Written loosely, they leak data; written tightly, they make many attacks impossible. Here is how to...
Overly broad bucket policies are a frequent root cause of S3 exposures. Detecting policy changes that widen access — and catching risky policies already in...
The short version: In 2017, a Verizon vendor exposed customer records — including account PINs used for phone support — in a cloud storage folder anyone...
In June 2017, researcher Chris Vickery of UpGuard found an Amazon S3 bucket containing personal data on about 198 million American voters. It belonged to...
Public S3 buckets were behind dozens of data leaks in 2017. AWS has since made buckets private by default, but older accounts, older buckets and deliberate...
The best time to catch a public S3 bucket is the moment it becomes public. Detection rules on configuration changes close the window between a mistake and...
The short version: In 2017, a data company working for the Republican National Committee left personal details on 198 million voters in an unprotected cloud...
On February 28, 2017, Amazon S3 in the US-EAST-1 region became unavailable for about four hours. Thousands of websites and apps stopped working, and even...
Amazon S3 is extremely durable, but a single region can still become unavailable. Here is how to design S3-backed workloads to keep running — or at least...
Outages are rare enough that teams forget how to handle them. A tabletop exercise — a structured discussion of a realistic scenario — is the cheapest way to...
The short version: In 2017, a mistyped command at Amazon took down a core storage service in one region for about four hours, and thousands of websites went...
At AWS re:Invent in late 2016, Amazon announced AWS Shield, its managed DDoS protection service. The headline was simple: every AWS customer would get...
AWS Shield Standard protects every AWS account against common network-layer DDoS attacks automatically. Application-layer attacks need more work. Here is...
Use this checklist to check whether an AWS-hosted application is ready for a denial-of-service attack. Each "no" is a gap to plan for.
The short version: Every AWS customer gets Shield Standard free, and it handles the most common DDoS attacks. Shield Advanced is a paid upgrade that adds...