3 ms·
Whilst not being a "cloud is someone else's computer" adherent, the notion SaaS products can't be misconfigured into opening up security holes not present / so
by jsty 6y ago
Whilst not being a "cloud is someone else's computer" adherent, the notion SaaS products can't be misconfigured into opening up security holes not present / so serious in some on-prem environments doesn't hold water - see the last decade's stories of accidentally open S3 buckets, plaintext secrets pushed to public GitHub repos, and all manner of other "minor misconfigurations"
- acdha 6y agoThis is true but there’s a big difference in how easy it is to audit. You can enable Security Hub and Guard Duty on AWS organization-wide in a few minutes and have a pretty solid baseline for hardening your infrastructure and flagging suspicious activity. Doing the same with on-premise infrastructure takes months and entails significant risk since things weren’t designed around APIs and low-privilege IAM. (GCP is similar but SCC is earlier in the development cycle and their threat detection isn’t well designed.)