TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Tell HN: AWS does not require email confirmation for email or password changes

18 点作者 schneiderscode超过 2 年前
Hey everyone,<p>I created a new AWS account over the weekend for a hobby project. Tonight I got an email that my password and email had both been changed. I hadn&#x27;t set up MFA yet simply because I hadn&#x27;t even used any resources.<p>I&#x27;m just shocked that Amazon doesn&#x27;t even send a &quot;Hey we&#x27;re about to lock you out, is this okay?&quot; email before allowing someone to completely take over.<p>As for the compromise, waiting to hear back on how this happened. I confirmed the password I used isn&#x27;t in haveibeenpwned. A keylogger seems unlikely since none of my other sensitive accounts have had issues. Just in utter disbelief that account changes would be allowed without any confirmation.

2 条评论

aborsy超过 2 年前
Interested how it happened.
klysm超过 2 年前
Was the password unique?