logo

The Unauditable, Unmanageable HMAC Keys in Google Cloud by Kat Traxler

ID: c6dbf76e-5b45-5e8d-8804-871ec2cc0a93

STIX ID: report--c6dbf76e-5b45-5e8d-8804-871ec2cc0a93

Feed Name: Vectra AI Blog

Threat Score
65/100

Date Published: 2024-06-17

Date Updated: 2026-05-01

...
...

**TL;DR:** The report describes three vulnerabilities in Google Cloud's handling of user-associated HMAC keys—insufficient logging of key creation/deletion, absence of admin APIs and IAM controls to audit or revoke user HMAC keys, and long-lived unauditable credentials that can be used to SigV4-sign Cloud Storage requests for up to seven days—providing an attack scenario, PoC, recommendations, and a disclosure timeline where Google closed the issue as intended behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.