Hacker News new | ask | show | jobs
by andrewstuart 2499 days ago
I had a simple glance in the console and there are like 20,000 exposed ebs snapshots - available for anyone to copy and examine - I think that's only for a single region too - switch regions to see more.

Amazon should make an emergency decision to make all these private.

Sure it will break stuff but I'd be disappointed if Amazon left what is in effect a security hole open for the sake of backwards compatibility.

They should also give me a single click link when I sign in to show me all of my public ebs snapshots and throw it hard in my face when I sign in to the console so I simply cannot avoid seeing them all.

I have multiple AWS accounts and I just signed in to try to see if I have any public EBS snapshots and then I realised I would need to search every single region in every single account and then select every snapshot one by one to find out. That's a huge problem. I need a single click to show me every exposed snapshot across every region in my account.

UPDATE:

I can't say for sure if this is 100% right but I think if you sign in to your AWS account, then click on each of these links, you will find if you have public snapshots.

Maybe someone else could confirm if this is correct?

https://us-east-1.console.aws.amazon.com/ec2/v2/home?region=...

https://us-east-2.console.aws.amazon.com/ec2/v2/home?region=...

https://us-west-1.console.aws.amazon.com/ec2/v2/home?region=...

https://us-west-2.console.aws.amazon.com/ec2/v2/home?region=...

https://ca-central-1.console.aws.amazon.com/ec2/v2/home?regi...

https://eu-central-1.console.aws.amazon.com/ec2/v2/home?regi...

https://eu-west-1.console.aws.amazon.com/ec2/v2/home?region=...

https://eu-west-2.console.aws.amazon.com/ec2/v2/home?region=...

https://eu-west-3.console.aws.amazon.com/ec2/v2/home?region=...

https://eu-north-1.console.aws.amazon.com/ec2/v2/home?region...

https://ap-east-1.console.aws.amazon.com/ec2/v2/home?region=...

https://ap-northeast-1.console.aws.amazon.com/ec2/v2/home?re...

https://ap-northeast-2.console.aws.amazon.com/ec2/v2/home?re...

https://ap-northeast-3.console.aws.amazon.com/ec2/v2/home?re...

https://ap-southeast-1.console.aws.amazon.com/ec2/v2/home?re...

https://ap-southeast-2.console.aws.amazon.com/ec2/v2/home?re...

https://ap-south-1.console.aws.amazon.com/ec2/v2/home?region...

https://me-south-1.console.aws.amazon.com/ec2/v2/home?region...

https://sa-east-1.console.aws.amazon.com/ec2/v2/home?region=...

1 comments

non-region console links should redirect OK if you're signed in - https://console.aws.amazon.com/ec2/v2/home#Snapshots:visibil...