{"version":"2.1.280","anchor":"aws-access-key-redaction-pattern-broadened","canonical_anchor":"aws-access-key-redaction-pattern-broadened","heading":"AWS access-key redaction pattern broadened","tier":"notice","area":"Permissions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280\/e\/aws-access-key-redaction-pattern-broadened","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280","markdown":"### AWS access-key redaction pattern broadened\n\nAWS access-key redaction in logs now covers more key-ID prefixes, not just AKIA and ASIA\n\n**What**\n\nThe pattern used to scrub AWS access keys from transcripts and logs previously matched only keys starting with `AKIA` or `ASIA`. It now also matches `ABIA`, `ACCA`, and the STS pattern `A3T[A-Z0-9]`, each followed by 16 alphanumeric characters, replacing matches with `<token>`.\n\n**Why**\n\nAWS issues credentials under several different prefixes; broadening the pattern reduces the chance that a real AWS credential of one of these other types leaks into a transcript or log unredacted.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}