4 ms·
> Lambda? Beanstalk? Glacier? EBS? What even is all this stuff. Yeah, well, if you don't understand something, you're not gonna recommend it. I'm glad they've
by TheIronMark 5y ago
> Lambda? Beanstalk? Glacier? EBS? What even is all this stuff.
Yeah, well, if you don't understand something, you're not gonna recommend it. I'm glad they've found a solution, but to make a blanket statement that no one needs cloud is just dumb.
also
> Identity management. You don’t need it.
Oh. Oh, no.
- jcvold 5y agoAgreed. Wait for tomorrow's blog post on this site titled: "Day 12: How to create a controversial post to generate traffic!"
- hn_throwaway_99 5y ago> Identity management. You don’t need it. I had the same "This is just ridiculous" thought when I saw that. The other thing I'd bet is that this person has never had to make sure their infrastructure can pass any kind of security questionnaire or compliance audit. My guess is they would fail in a heartbeat.
- Crosseye_Jack 5y agoMy takeaway from "Identity management. You don’t need it." was talking about AWS Cognito and not identity management as a whole. At least that is what I hope they meant.
- Tainnor 5y ago> The other thing I'd bet is that this person has never had to make sure their infrastructure can pass any kind of security questionnaire or compliance audit. Security audits are a big security theater more often than not, though. At my current workplace, I have to jump through several hoops to do certain things, but it doesn't change the fact that I (or some privileged service) am still the entity that is allowed to jump through all these hoops. I don't want to imply that IAM is necessarily bad, but it is complicated to understand and security is often negatively affected when there is friction involved. Then, processes are implemented that look secure, but they don't necessarily guarantee security and people find workarounds like sharing tokens, defeating the whole point of auditability.
- hn_throwaway_99 5y agoAgree 100%. I often get frustrated by things in GCP IAM that seem overly complicated (i.e. it's not at all easy to get a simple view of "show me all the resources this identity has access to"). But that said, at the end of the day you WILL need the concept of users, roles, permissions, and restricted access to resources based on those permissions. That's a ton of work if you're doing by yourself, and you're likely to get it wrong.
- izolate 5y agoIt's really disappointing to see the author fall victim to the thinking that whatever works well for their tiny use-case can be applied across the board. Honestly, this seems like an ill-attempt at garnering views to their startup-in-80-days endeavor with a clickbait article.
- paxys 5y ago> Honestly, this seems like an ill-attempt at garnering views to their startup-in-80-days endeavor with a clickbait article. Aka perfect HN bait