Skip to content

Commit

Permalink
Update service-catalog/gcp-backup/README.md
Browse files Browse the repository at this point in the history
Co-authored-by: Jan David <jdno@jdno.dev>
  • Loading branch information
marcoieni and jdno authored Sep 25, 2024
1 parent 9d9ca4c commit 89405a1
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion service-catalog/gcp-backup/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ These threats were identified in a [threat model] for the project's infrastructu
While we have multiple measures in place to prevent accidental deletion of Rust releases or crates in AWS,
e.g. bucket replication to a different region and restricted access, our current setup does not sufficiently protect us against a few threats:

1. _AWS Account compromise_. The [threat model] for Rust's infrastructure, created by the Rust Foundation's security engineer, highlights the risk of an AWS account compromise.
1. _AWS Account compromise_. The [threat model] highlights the risk of an AWS account compromise.
If a malicious actor was able to gain administrator access to the AWS account of one of the [infra-admins],
they could bypass a lot of safe guards and delete data.
2. _AWS Account deletion_. AWS could accidentally delete our account, resulting in the possible deletion of data and backups.
Expand Down

0 comments on commit 89405a1

Please sign in to comment.