3 ms·
> They install bitcoin miners. You can do that without root. > They install malware. What developers are you talking about? I want to know what developer wou
by voidr 8y ago
> They install bitcoin miners.
You can do that without root.
> They install malware.
What developers are you talking about? I want to know what developer would risk their career and prison time. And if a developer has no problem with going to prison, surely they have no problem finding some 0day privilege escalation exploit.
> It's unfortunate but it's true, I've seen it 100x.
That's not really an argument, how many developers did you have and how many of them risked prison time to install malware on dev machines?
> We take great measures to ensure that we can do that while still keeping our customers safe.
> We would never allow admin AWS access, that's absurd. An attacker on your box would be able to own prod.
You aren't doing a great job then, because your production stuff should be on a separate AWS account altogether.
- scarface74 8y agoEven if your production stuff is in a separate account, that just helps prevent someone from accidentally screwing up production. To think that not giving your developers - the people who are creating code that you are putting on your servers and know the infrastructure as well as anyone - will prevent them from being malicious is just security theatre. It may help you check the box about being compliant with some type of standard but it really doesn't help you. If the developers program has access to production resources, they can gain access to those resources.