8 ms·
Cleaning Up Dead Bodies in AWS IAM
- urahara 3y agoJust to get an idea of where your solution stands on the market, what tools are you competing with and what "CSPM/CIEM tools that fall short in cleaning up AWS IAM" do you imply?
- shortrounddev2 3y agoAt my last company they asked me to find all the users who no longer needed access to our AWS account, as well as create a report for teams to review if each of their members needed access to the roles they have access to. It took a little bit to understand the IAM model, but I created dozens of reports for a few hundred engineers. Dead users were deleted, but literally nobody reviewed group access with the reports I sent out. Just one of many projects I did for a VP where there was no active demand for that project. VP was made redundant shortly after
- skuenzli 3y agoCan you share what the high-level goal of the project was? i.e. was the VP trying to reduce risk? scale out responsibility for managing access?
- steveBK123 3y agoThis is the sort of ladder-climbing VP behavior you see from someone who is too concerned about avoiding failures that they don't actually do anything productive. Don't launch any projects in a firm direction because if they fail, it's a failure of commission. Wastes lots of time churning what-if scenarios, blocking things & generating reports no one wants in case he gets asked for them, so he can't be accused of a failure of omission. It's the 3d chess played by someone who forgets what their actual day job is - getting shit done.
- vrosas 3y agoIf I’ve learned anything, the only people who care about doing things are at the very, very bottom. No one up the chain actually cares about doing things. They talk about doing things, present grand slidedecks internally and at conferences about doing things, have project/product/engineering managers constantly planning on doing things and thinking about better/faster ways to do them. But really there’s an entire pyramid of people in the company just kind of keeping themselves busy while the grunts at the bottom turn out as much as their hands can muster while desperately hoping to one day be a non-doer (or move to yet another company where they’re promised they’ll _actually_ do things but really it’s the same exact company with a different logo).
- gabereiser 3y agoYou guys have it so wrong. Their job is to get you to do things. With slide decks. Presentations. Speeches. Roadmaps. Stories. Visions. Carrots. That’s their job. As well as to aggregate the litany of statuses into an über status at the end of the week/month/quarter so that their higher ups see work being done. What they do is different from what you do so you only see them not doing what you’re doing, not what they are doing. However, if we are going to generalize, yes - you are correct on the fact that they spend their time thinking about better/faster without making it better nor faster (mostly the opposite). They have context into why you are doing something, even if you don’t.
- steveBK123 3y agoIn a working org you are right. In many orgs measurement of work takes precedence over actually achieving work.
- bfbmrlr 3y ago[flagged]
- gabereiser 3y agoAll hail the oracle KPIs and OKRs to save the organization and steer us towards redemption…
- shortrounddev2 3y agoReducing risk, yes, but I think the VP just sat around thinking of project ideas that sound useful without asking around to see if relevant stakeholders are actually interested
- skuenzli 3y agoThanks for the additional context. Agree that leaders should definitely be ready to motivate stakeholders and collaborating teams to act on this kind of info before spending significant time gathering & producing it.
- res0nat0r 3y agoI'm dealing with the same type of nonsense currently, as an internal audit team sees security groups being flagged by the scanning software that are open to 0.0.0.0/0 which is automatically "bad", even though the hosts have no public IP's and are being automatically managed by EKS to setup links to k8s NodePorts and the ELB. Same with security groups. Gartner has some "best practice" doc somewhere, someone loads that into a security tool, the tool flags things, and these checkboxes must go from red to green. The technical hurdles to comply or actual value do not matter.
- bravetraveler 3y agoI'm still on the platform side, out of K8s and the like - but this is so painfully true. They try to tailor a lot of these things to the OS/distribution, but fail in the most wonderful ways. A recent example: they're aware of RHEL. They're also aware of 'firewalld'. However, they have not managed to realize that this is simply a management interface to other firewalls -- imposing standards on a long-deprecated backend; iptables Meanwhile, using incredibly inefficient and 'portable' command lines. ie: using find in such a way that an LDAP query happens for every file Refusing to use the arguments available to the operating system they 'tailor' for. Ultimately timing out once you hold a certain number of files.
- eddd-ddde 3y agoI find interesting the last example with find and ldap queries. I'm not too familiar with ldap, but i do use find frequently. Could you expand on the example and what happens and why it's bad?
- bravetraveler 3y agoCertainly! In this case, they were interested in files that were too permissive. I don't have a good example of the command, but it was basically looking for 'worldly' permissions that were too open. It's important to note the users/groups could be discarded/ignored. They were using 'find ... -exec ls -ld {} \;', which does an LDAP lookup on each result to resolve UIDs and GIDs to names. They could have made the process far more efficient with either the native '-ls' argument built into find, or adding '-n' to the exec'd 'ls' Either would skip the name resolution/domain. At a certain number of results/files the expense is too high, causing the job to time out
- icedchai 3y agoOften creating work is a goal in itself. You gotta justify all those people somehow.
- AtlasBarfed 3y agoACLs/Policies (especially the very fine-grained ones used by AWS now) + groups + roles + users + resources Probably maps to the SAT / NP-complete space. Congrats! Management of security permissions is virtually guaranteed to be non-polynomial.
- scarface_74 3y agoWhy did you have users in your AWS account besides a couple of emergency break glass users? All other users should have been going through some SSO using Microsoft AD, Okta, etc.
- shortrounddev2 3y agoI did not come up with the system
- securiy 3y agoIAM users are still needed in large orgs because of legacy tooling that only accepts access key ID / secret access key sigh.
- happytoexplain 3y ago>Discover why conventional CSPM/CIEM tools fall short in cleaning up AWS IAM, and explore a better solution with Noq and IAMbic We live in a noun hell where every technical topic has a high barrier to entry that makes it hard to casually learn anything. It's difficult to be even a traditional generalist in this ecosystem, and yet the market treats people as if the only way to be considered valuable is to be a super generalist (depth + breadth).
- rustyminnow 3y agoYou don't need to know the acronyms to understand the article. Use context clues to infer that the author's point is "traditional tools don't solve the problem I am about to present". They even expand the acronyms later in the article. Besides, most such acronyms for classes of security tools don't actually mean much. They just represent the current flavor of the week in the security arms race.
- n6h6 3y ago> They even expand the acronyms later in the article. That's the OPPOSITE of how you're supposed to use acronyms. If you're going to spell it out anyway, why not do it the first time you talk about it like you're supposed to?
- beckler 3y agoAcronyms are the worst. I guess people do it to sound cool or something, but I once maintained a legacy project that had an acronym for a name. Not a single person working at the entire company knew what the acronym originally meant, and of course, it was never documented.
- colinrand 3y agoAnalyst firms (ie Gartner) are a big driver of this too. Couple that with the start up / VC model which needs to create new 'categories' to demonstrate differentiation, and you have a total mess.
- huslage 3y agoThis website is marketing nonsense. I need to understand the technical underpinnings of it. Why does this help me?
- deleted 3y ago[deleted]
- Cthulhu_ 3y agoIf you don't see how it helps you, you probably don't need it. Either because it's not a problem you have or deal with, or because the site doesn't flag up anything with you.
- justin_oaks 3y agoWhile there's merit to that idea, we don't want to discourage people learning, do we? Ideally we'd learn about other people's problems BEFORE they become our problems so we're prepared to deal with them. Or we can just want to expand our realm of knowledge.
- ams92 3y agoManaging IAM is a pain in the ass on AWS. I can’t speak to how much this product actually helps with that, but I would assume that that’s the problem they’re trying to solve.
- deleted 3y ago[deleted]
- poxrud 3y agoI've made it a habit to only create IAM roles/users/policies using CloudFormation. This way they can be easily removed, are version controlled and you can see why they were created in the first place.