fwd:cloudsec Europe 2024

GCP and AWS identity federation - lessons learned from the field as well as cross-cloud forensics and incident response.
09-17, 16:00–16:20 (Europe/Brussels), Main Room

Our presentation is about identity federation between GCP and AWS using AssumeRoleWithWebIdentity. We will share our setup and lessons learned from implementing this in production at Spotify, as well as how we verify service identity between different cloud providers. Additionally, we will discuss the setup for use cases such as cross-cloud forensics and incident response.

In our session we’ll deep dive into the AssumeRoleWithWebIdentity API and show how we can use it together with both native cloud SDKs as well as building our own self-signed token service to automate various use cases. Our presentation will cover:
- Deep dive into identity federation between GCP and AWS using AssumeRoleWithWebIdentity
- Our journey implementing this in production and our lessons learned.
- Demonstrating how this can be used for cross-cloud forensics and incident response purposes. E.g. collecting forensic artifacts between GCP projects and AWS accounts.

We’ll also cover options for how to automate the above methods for cross-cloud forensic purposes.

See also:

My name is Marcus, a security engineer at heart, and I work for Spotify in Stockholm, Sweden. I spend my time with a mix of detection and response as well as cloud security where my passion is in forensics and automation. When I have time off I enjoy rock climbing, folk dancing and cross-country skiing.

My name is Attila, a security engineer who is a fan of codified solutions which aim to reduce the burden of the users by helping them to configure things easier and safer. My current day to day focus is mostly around Cloud Security and Cloud IAM problems . In my free time I like doing strength training, hiking, and practicing inline skating tricks at skateparks.