top | item 45533663

(no title)

knert | 4 months ago

I’m not sure this is true. The EC2 web console terminal drops me right into root on any of my instances.

discuss

order

placardloop|4 months ago

Ahh you’re right, there are some that just initiate a connection via something like Session Manager, but those connections where AWS initiates the connection for you are logged in CloudTrail, even without data events, and root doesn’t give you any ability to directly SSH into an instance outside of those methods (you cannot, for example, use root to find out what the private keys are for logging into an instance) so we’re back to the fact that any such access would be auditable.