3 ms·
FWIW, more debugging information in an IAM failure is another round of information available to me as an attacker. If such a service existed available to the cu
by devonkim 3y ago
FWIW, more debugging information in an IAM failure is another round of information available to me as an attacker. If such a service existed available to the customer this also becomes potentially available to an attacker. In fact, it may wind up violating a few companies’ security and compliance policies.
However, I think that customers should have the option once they sign some stuff acknowledging that they may be really, really screwed similar to Bad Things done as a root user in AWS.
Given the distributed nature of so many requests in AWS I’d imagine that a GraphQL-like setup would be conceptually compatible with such a system. It’s not terribly far from tracing systems like OTEL
- nprateem 3y agoFor some APIs they return encrypted payloads with actually useful debugging info in, but there seem to be plenty where you just end up in a black hole of "computer says no"
- JoBrad 3y agoThey could put better information in Cloudtrail, at least.
- booi 3y agoThey do! Most all IAM errors will list the actor, the resource, and the missing permission