Skip to main content

All Questions

Tagged with
Filter by
Sorted by
Tagged with
1 vote
1 answer
292 views

Does this official "Enforce MFA" AWS policy make any sense?

At https://aws.amazon.com/premiumsupport/knowledge-center/mfa-iam-user-aws-cli/ the AWS officially recommends to have this policy { "Sid": "...
zerkms's user avatar
  • 173
6 votes
1 answer
2k views

How is a bad actor able to disable Amazon's 2-step verification without supplying a OTP?

My wife's Amazon account was hacked yesterday. She discovered the purchases, changed her password to both gmail and Amazon, and enabled Amazon's 2-step verification (2FA) through SMS on her phone and ...
Mordred's user avatar
  • 203
6 votes
2 answers
519 views

Security mechanism differences between Google and Amazon APIs

Does anyone know why Google and Amazon (AWS)'s API have such different ways to deal with security? For example, Google has a simple API key which you can revoke at any time, while Amazon has this ...
Nicolas Bouvrette's user avatar
0 votes
1 answer
4k views

How do you log into Amazon Web Services if you lose your phone which has Google 2-factor authentication set up?

And if it is possible, how do you prevent other people from claiming they are you and lost their phone? Amazon only directs you to a page which does not exist. http://aws.amazon.com/iam/faqs/ If ...
Chloe's user avatar
  • 1,788