15 ms·
> While I wouldn't call AWS security "broken," ... That doesn't match with the rest of your comment. At all. What would you call broken, then?
by aptwebapps 9y ago
> While I wouldn't call AWS security "broken," ...
That doesn't match with the rest of your comment. At all. What would you call broken, then?
- cddotdotslash 9y agoThe security itself is sound. AWS has very very few security incidents where their security was compromised. KMS hasn't been broken (to anyone's public knowledge). If you mark an S3 bucket as private, they've never been accidentally exposed at the fault of AWS. The issue is in the user's use of the security features. Do you call bcrypt broken if someone uses a weak password and only 1 round of salting? Do you call TLS broken if someone misconfigures their NGINX installation?