The Unauditable, Unmanageable HMAC Keys in Google Cloud by Kat Traxler
ID: c6dbf76e-5b45-5e8d-8804-871ec2cc0a93
STIX ID: report--c6dbf76e-5b45-5e8d-8804-871ec2cc0a93
Feed Name: Vectra AI Blog
Threat Score
**TL;DR:** The report describes three vulnerabilities in Google Cloud's handling of user-associated HMAC keys—insufficient logging of key creation/deletion, absence of admin APIs and IAM controls to audit or revoke user HMAC keys, and long-lived unauditable credentials that can be used to SigV4-sign Cloud Storage requests for up to seven days—providing an attack scenario, PoC, recommendations, and a disclosure timeline where Google closed the issue as intended behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
