Someone had gotten ahold of one of my security keys and I stupidly didn't have 2-FA enabled.
They spun up dozens of EC2's with high-end GPU's mining crypto and managed to rack up a $600 bill before AWS flagged it and halted activity + contacted me by email.
I was surprised to learn that AWS support does not have any sort of automated tooling for large-scale service wipes. I asked them just to nuke any AWS service attached to my name, as I had no personal projects or databases I needed to keep.
They couldn't do this, and it was a lot of hand-cleaning and using some public tools from Github.
I refused to pay the $600 and now my AWS account is permanently closed.
Lesson learned: If you have your credit card attached to something, immediately enable 2-FA.
HenryBemis•1d ago
[0]: https://i.imgur.com/T8BmaVd.jpeg
hluska•1d ago
southernplaces7•1d ago
HenryBemis•1d ago
The 'amusing' part is... since the first time I encountered "DevOps" I thought that it is a terrible idea (but what do I know...). There are some stupid buzzwords that became the norm and I thought they were moronic/creepy/dangerous form the fist time I heard them (and I was spot on). DevOps is one. It's like saying "someone eats swords for a living" and "that very someone pierced his stomach". I will feel sorry for the fella and will wish him speedy recovery, but I will whisper to myself "what a f... moron".
Also, due to my Audit/Sec/GRC background, I laugh when I read/hear such stories because "you auditors know shit, we don't need ITGCs" and plenty other stupid shit that I hear from Tech Bros. Well, how do you like them apples/ITGCs now??? So, don't try to bark at the one who laughs. Instead punch the moron who says "we don't need ITGCs, documentation, reviews, etc, they are a waste of time".
So.. sorry, not sorry (at all).
EDIT: as you can understand this is a sensitive topic for me, because ITGCs cause time/money, but hey, go ask those DevOps, (now) would they prefer to have ITGCs are X cost in time, or they prefer the loss? And seeing that they have BAD IT practices who will ever trust them again to do something right?
southernplaces7•1d ago