Doing bad things for the right reasons: A look at the AWS vulnerability disclosure and remediation process

No ratings

Presented at fwd:cloudsec Europe 2024 by

# Summary In an era where cloud services form the backbone of our digital infrastructure, uncovering cloud vulnerabilities and ensuring their responsible disclosure is paramount. This session will explore key aspects of responsibly disclosing security research findings in cloud environments. Topics include the research process, how researchers approach cloud services, addressing Coordinated Vulnerability Disclosure (CVD), embargo periods, strategies for customer protection, and real-world examples. https://aws.amazon.com/security/vulnerability-reporting/ # Outline: * How does a security researcher approach cloud services * Coordinated Vulnerability Disclosure (CVD) * A vulnerability has been identified. What's next? * AWS workflow * Real world examples * What are Embargo periods? * What is Public disclosure? * Where to Report?