HomeSecurityOlympic Games: Security weakness in their systems?

Olympic Games: Security weakness in their systems?

The 2020 Tokyo Olympics are one of the main topics of discussion around the world. The Summer Olympics, as they are also called, were canceled last year due to the COVID-19 pandemic and this year they finally managed to take place. But what about the security of their systems? We imagine that since this is an event that draws all eyes on it, security would be at very high levels! But it seems that things are not as we imagine.

Olympic games

See also: Kaseya REvil ransomware: Company obtained decryption key

According to security researcher Chris Vickery, who posted a tweet that you can see below, credentials from Amazon access keys related to the websites and systems of the Olympic Games were exposed. What are these systems? The researcher refers to Eurosport, which states in its description that it is the “home” of the Olympic Games, and the well-known Discovery.

Dor also: US: Accuses China of committing ransomware attacks

But let's take a closer look at what it means to expose Access Keys (Access Tokens)

Typically, when we think of credentials, the first thing that comes to mind is a username and password that are widely used by individuals and other systems to authenticate to systems. But in software, there is an additional type of security credential – an access key. Access keys can be public or private and, depending on the type of service, provide system authentication to third parties or internal systems. Access keys often have broader access than individuals and fewer controls/restrictions on their use.

Unfortunately, these access keys can be exposed by software developers or contractors, who may not have noticed that a repository's settings have been changed to public. A study by North Carolina State University found that over 100,000 GitHub repos have leaked API or cryptographic keys.

security vulnerability

See also: Israel: Anti-ransomware campaign to tackle the threat

Who is at risk?

Databases, cloud storage and other services are at risk from exposed access keys, reports a related study by Digital Shadows.

Over a 30-day period, Digital Shadows scanned more than 150 million entities from GitHub, GitLab, and Pastebin.

During this month-long study, Digital Shadows evaluated and categorized nearly 800,000 access keys and secrets.

More than 40% of these exposed credentials were for database stores, while 38% were for cloud providers, such as Google, Microsoft Azure, and Amazon Web Services.

Google Cloud Platform was found to have the most exposed keys, with 56.5% of the total. Microsoft Azure access keys and SAS tokens accounted for 22.7% and 12.4% respectively. Although Amazon Web Services is the market leader, exposed keys for these services only made up 8.3% of the total.

What could happen to the Olympics?

Hackers with the proper handling of these access keys could do almost anything: gain access to sensitive files, make changes to the servers, or even manage to interrupt the broadcast of the Olympic Games! However, we are definitely talking about a very serious leak and we will keep you informed for additional information!

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS