3 ms·
I'm fully aware of those risks. The issue for me is a matter of realism. A combination of the default policy being poor on all AWS services, the shared respons
by wrldos 4y ago
I'm fully aware of those risks. The issue for me is a matter of realism.
A combination of the default policy being poor on all AWS services, the shared responsibility model of AWS delegating this risk to clients and the default security posture in the industry being terrible makes the real problem of solving this like traipsing across a field covered in poo.
An analogy; you have to tick the box to put your front door key under the doormat. The burglar knows where the hole in your fence is and knows you might keep your keys under the door mat. Plus your kids left their keys on the github bus.
Of course the SOC2 audit says you ticked the box and you tell everyone your house is a castle.