AWS Backup Vault Lock security gap exposes encrypted backups to key deletion risk
A DEV Community article reveals a security oversight in AWS Backup Vault Lock implementations. While the vault itself prevents deletion of recovery points, the customer-managed KMS keys encrypting it remain vulnerable. Account administrators can disable or schedule deletion of these keys, rendering backups unreadable. The article details attempts to protect keys with cross-account break-glass roles, but AWS restrictions prevent external administration of KMS keys. This leaves regulated workloads potentially exposed despite using compliance-focused backup features.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in