4 items across 2 sections
How I built CognitoApi, an open-source serverless authentication API on AWS Cognito that handles 50,000 users for free with MFA, token management, and complete user lifecycle support.
Part 8 of 16 in the AWS Security Agent: From Zero to Hero series. I ran the same pentest twice against the same application. The only change was providing a username and password. Findings went from 5 to 13, a 160 percent increase, including two critical JWT bypasses and a privilege escalation.
Comprehensive guide to securing Amazon API Gateway. Covers authentication with Cognito and Lambda authorizers, mutual TLS, WAF integration, resource policies, throttling and usage plans, private APIs with VPC endpoints, access logging, SSL/TLS enforcement, and request validation.
Comprehensive guide to securing Amazon Cognito user pools and identity pools. Covers MFA enforcement, advanced threat protection, password policies, WAF integration, JWT verification, Lambda trigger security, and identity pool least privilege.
Our AWS security experts can help you implement best practices across all these topics.
Contact Us