Description
Short or predictable IAM console passwords can be vulnerable to guessing. Adding length does not adequately protect a reused or widely known password.
Potential impact
A guessed password can allow misuse of the account’s permissions.
Remediation
Use unique passwords meeting the organization’s length requirement and enable MFA. If the baseline is at least 14 characters, enforce that or longer in the account password policy.
Examples
These excerpts illustrate length only. Do not use the displayed passwords for real accounts; supply production passwords through secure input or secret management. Referenced resources are omitted.
Before
yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: Password length comparison
Resources:
myuser:
Type: AWS::IAM::User
Properties:
Path: "/"
LoginProfile:
Password: myP@ssW0rd
Policies:
- PolicyName: giveaccesstoqueueonly
PolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Action:
- sqs:*
Resource:
- !GetAtt myqueue.Arn
- Effect: Deny
Action:
- sqs:*
NotResource:
- !GetAtt myqueue.Arn
- PolicyName: giveaccesstotopiconly
PolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Action:
- sns:*
Resource:
- !Ref mytopic
- Effect: Deny
Action:
- sns:*
NotResource:
- !Ref mytopic
After
yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: Password length comparison
Resources:
myuser:
Type: AWS::IAM::User
Properties:
Path: "/"
LoginProfile:
Password: myP@ssW0rd123asw
Policies:
- PolicyName: giveaccesstoqueueonly
PolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Action:
- sqs:*
Resource:
- !GetAtt myqueue.Arn
- Effect: Deny
Action:
- sqs:*
NotResource:
- !GetAtt myqueue.Arn
- PolicyName: giveaccesstotopiconly
PolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Action:
- sns:*
Resource:
- !Ref mytopic
- Effect: Deny
Action:
- sns:*
NotResource:
- !Ref mytopic