3 ms·
AWS is so difficult to use securely by default that there is an entire thriving industry of vendors who will analyze your permissions and try to bring them down
by drunkpotato 5y ago
AWS is so difficult to use securely by default that there is an entire thriving industry of vendors who will analyze your permissions and try to bring them down to meet the standard of principal of least privilege. I'm not at all surprised that there are many insecure environments and privilege escalation exploits; AWS is almost aggressively hostile to any attempts to use it securely.
- mise_en_place 5y agoThis is completely untrue. AWS offers many tools to audit credentials. It also has the policy simulator to see exactly what the impact of changes will be on a role.
- fivea 5y ago> This is completely untrue. AWS offers many tools to audit credentials. It also has the policy simulator to see exactly what the impact of changes will be on a role. Your comment fails to prove, or suggest, that OP's claim that AWS is too difficult to use securely by default is false. To first be in a position to refute OP's point you would need to prove, for starters, that no such vendor exists, which is absurd because they do exist, don't they? In fact, if anything it supports OP's claim, as you've just pointed out that AWS even tries to profit from their problem of making it too difficult to use it securely by default by selling a premium service to audit credentials.