3 ms·
The IAM policy shown on the website allows sts:AssumeRole without any restricting on resources or conditions which will be a deal breaker for many. Presumably
by FujiApple 5y ago
The IAM policy shown on the website allows sts:AssumeRole without any restricting on resources or conditions which will be a deal breaker for many. Presumably you can restrict this to certain AWS principals?
- gigatexal 5y agoYeah this should be addressed. Also kudos I guess for landing kik as a customer.
- kavehkhorram 5y agoHi FujiApple, We use the sts:AssumeRole policy to create temporary short-lived credentials for us to get access to the AWS APIs on your behalf. The assume role permission is constrained only to the policy we've defined on our landing page and in our app, which are read-only + the ability for us to manage your reservations on your behalf.