logoalt Hacker News

a2techtoday at 2:14 PM7 repliesview on HN

AWS support seems to be struggling. I just came to help a new customer who had a rough severance with their previous key engineer. The root account password was documented, but the MFA went to his phone.

We've tried talking to everyone we can, opening tickets, chats, trying to talk to their assigned account rep, etc, no one can remove the MFA. So right now luckily they have other admin accounts, but we straight up can't access their root account. We might have to nuke the entire environment and create a new account which is VERY lame considering they have a complicated and well established AWS account.


Replies

mhurrontoday at 3:26 PM

Amazons assistance for account issues to organizations if an employee did anything individually is honestly horrible.

They treat it like the organization is attempting to commandeer someone else's account so all the privacy protections you expect for your own stuff is applied no matter how much you can prove it is not some other individuals account.

The best part is the billing issues that arise from that. In your example, if the previous engineer logged into that account (because they can) and racked up huge costs, assuming that account is getting billed or can be tied to your client, Amazon will demand your client pay for them, while at the same time refusing to assist in getting access to the account because it's someone else's. They hold you responsible, but unable to act in a responsible manner.

show 1 reply
senkoratoday at 4:17 PM

Is this something where you could pay a "consulting fee" to the previous key engineer to login and remove the MFA?

I know that that's not ideal, but as a practical matter perhaps it would be easier than creating a new account, if you can get the engineer to agree to it?

kevin_thibedeautoday at 2:35 PM

This is why you either issue corporate phones or key dongles.

show 1 reply
NetMageSCWtoday at 2:50 PM

What happens when someone loses their phone?

show 1 reply
nradovtoday at 6:07 PM

I won't attempt to defend AWS here, but if any company has such incompetent IT management as to allow an individual employee to have that level of control then they kind of deserve what they get. Life is hard when you're stupid.

UltraSanetoday at 3:15 PM

This is why you never use personal phones for MFA to critical accounts.

dixie_landtoday at 4:15 PM

I named random Joe as the sole owner of "my" bank account and the bank wouldn't allow me to access "my" money!

show 2 replies