3 ms·
I feel like this is the real base problem here. There's an incredibly broad set of permissions (at the cloud or OS level). Any app / tool may be written to use
by ethbro 6y ago
I feel like this is the real base problem here.
There's an incredibly broad set of permissions (at the cloud or OS level). Any app / tool may be written to use any subset of those. And what it uses is rarely documented (because developers don't see IAM security as a primary feature, outside of apps intended for use in regulated environments).
Without automation, this thus requires continual reverse engineering, which is never a healthy, sane long-term solution.
This should be fixed on the product / app side, where folks are much better placed to dump "I need this, and only this" in machine-readable form.