Create an Account
username: password:
 
  MemeStreams Logo

AWS signature version 1 is insecure

search

Lost
Picture of Lost
My Blog
My Profile
My Audience
My Sources
Send Me a Message

sponsored links

Lost's topics
Arts
Business
Games
Health and Wellness
Home and Garden
Miscellaneous
Current Events
Recreation
Local Information
Science
Society
Sports
Technology

support us

Get MemeStreams Stuff!


 
AWS signature version 1 is insecure
Topic: Technology 6:47 am EST, Dec 23, 2008

The important bit first: If you are making Query (aka REST) requests to Amazon SimpleDB, to Amazon Elastic Compute Cloud (EC2), or to Amazon Simple Queue Service (SQS) over HTTP, and there is any way for an attacker to provide you with data which you use to construct your request, switch to HTTPS or start using AWS signature version 2 now.

Perhaps this is why Amazon broke version 1 in the Perl lib a few days ago.

AWS signature version 1 is insecure



 
 
Powered By Industrial Memetics
RSS2.0