Noah McDonald

71 posts

Noah McDonald

Noah McDonald

@TheIceRoot

GCP Consultant @googlecloud | Ex-Unit42 | Cloud Security | @[email protected]

शामिल हुए Mart 2022
144 फ़ॉलोइंग78 फ़ॉलोवर्स
Dr. Anton Chuvakin
Dr. Anton Chuvakin@anton_chuvakin·
Some org: "We want to use AI to solve this hard security problem X" Also, SAME org: "What's event correlation? How do we enable it in our SIEM?" #facepalm #overheard
English
9
3
68
13K
Noah McDonald रीट्वीट किया
kat traxler
kat traxler@NightmareJS·
I was recently pointed to some #fresh GCP documentation from @TheIceRoot For your reading pleasure is a complete list of P4SAs (per-project-per-product) Service Accounts and their default roles 📯 cloud.google.com/iam/docs/servi…
English
1
4
8
1.3K
Noah McDonald रीट्वीट किया
fwd:cloudsec
fwd:cloudsec@fwdcloudsec·
We've lined up a venue for fwd:cloudsec 2024! Mark your calendars for June 17-18 in Arlington, VA. Ticket sales and CFP will open in early January. For those interested in sponsoring, we'll have a prospectus in the next few weeks. Email sponsorship@fwdcloudsec.org if interested.
English
0
20
72
13.4K
Noah McDonald रीट्वीट किया
SecTor Security Con
SecTor Security Con@sectorca·
Ever wonder how attackers breach the cloud? Jay Chen and Noah McDonald will walk through common cloud attack vectors and a real breach incident in this #sectorca presentation, starting at 2:45 in 714AB. buff.ly/3tuDMxt
SecTor Security Con tweet mediaSecTor Security Con tweet media
English
0
1
1
120
Noah McDonald रीट्वीट किया
SecTor Security Con
SecTor Security Con@sectorca·
85% of organizations have hard-coded credentials in VMs, say Jay Chen and Noah MacDonald. Their talk on cloud oversight is ongoing at #sectorca in 714AB. buff.ly/3tuDMxt
SecTor Security Con tweet mediaSecTor Security Con tweet media
English
0
1
1
112
Noah McDonald रीट्वीट किया
SecTor Security Con
SecTor Security Con@sectorca·
We just heard all about how upset gamers compromised the cloud with SIM-Swap, thanks to Jay Chen and Noah McDonald at #sectorca. They're wrapping up now in 714AB. buff.ly/3tuDMxt
SecTor Security Con tweet mediaSecTor Security Con tweet media
English
0
1
1
117
Noah McDonald
Noah McDonald@TheIceRoot·
If you are at #SecTor today, come check out my talk on real world cloud attacks! #cloud #blackhat #when-the-external-threats-and-internal-risks-meet-a-story-of-cloud-breach-34088" target="_blank" rel="nofollow noopener">blackhat.com/sector/2023/br…
English
0
0
2
74
Noah McDonald
Noah McDonald@TheIceRoot·
@NightmareJS Agreed, but people can easily do a better job of locking down their service accounts. It’s up to us to educate them :)
English
1
0
2
90
kat traxler
kat traxler@NightmareJS·
@TheIceRoot This one is so hard because cross-project SA assumption is also a feature of good architecture 🖤
kat traxler tweet media
English
1
0
3
263
Noah McDonald
Noah McDonald@TheIceRoot·
I am excited to announce that my colleague Jay Chen and I got accepted to @BlackHatEvents SecTor!! #when-the-external-threats-and-internal-risks-meet-a-story-of-cloud-breach-34088" target="_blank" rel="nofollow noopener">blackhat.com/sector/2023/br…
English
0
0
6
960
Noah McDonald रीट्वीट किया
kat traxler
kat traxler@NightmareJS·
Unfortunately @orcasec got their terminology wrong in their report by calling the cloud build SA , a ‘Default SA’, then I PERPETUATED it! - apologies. There are only 2 default SAs. The compute and app engine SA. The Cloud Build SA is not a default SA, it is a P4 SA. 1/3
kat traxler@NightmareJS

The "bad.build" in question is the Default Cloud Build Service Account (SA), so what is it? It runs build for you, pulls images, injects secrets and "actsas" the SA which any resulting resource (i.e. Cloud Run) ultimately runs as. They are unique per project. 2/8

English
2
2
12
2.8K
Noah McDonald
Noah McDonald@TheIceRoot·
@cloudvillage_dc @defcon How long until the submitters should hear back? I haven’t received an approval or denial email yet
English
0
0
0
56
Cloud Village
Cloud Village@cloudvillage_dc·
Just wrapped up the exhilarating task of reviewing all the impressive entries for @defcon this year 🎉📚 Massive kudos to all of you who submitted their work. We will be reaching out to the speakers soon ☎️ Stay tuned for an epic lineup coming your way! 👀 #cloudsecurity #dc31
GIF
English
3
7
21
4.8K