3 ms·
The Privilege Escalation attack vector can be avoided by using a capability-based security model, ala: https://storj.io/blog/2019/12/secure-access-control-in-t
by kevinStorj 7y ago
The Privilege Escalation attack vector can be avoided by using a capability-based security model, ala: https://storj.io/blog/2019/12/secure-access-control-in-the-decentralized-cloud/ https://storj.io/blog/2019/12/secure-access-control-in-the-d...
- donavanm 7y agoHow is this relevant? AFAICT AWS Policy statements are capabilities. Each policy statement denotes both actions and resources, and that policy is then granted to another identity/resource. As noted by other comments the parent article focuses on capabilities that grant definition of capabilities. It shouldn't be surprising that principals can use that to establish further capabilities in the absence of other restrictions.