4 ms·
> "This entirely separate attack exists therefor completely removing an entire attack primitive haves no value" It has value, but it's also true that trusting
by tg180 3y ago
> "This entirely separate attack exists therefor completely removing an entire attack primitive haves no value"
It has value, but it's also true that trusting cloud providers serveless infrastructure introduces additional sets of vulnerabilities due to various reasons.
eg: https://sysdig.com/blog/exploit-mitigate-aws-lambdas-mitre/ https://sysdig.com/blog/exploit-mitigate-aws-lambdas-mitre/
Reading your comments, I get the impression that you are used to dealing with clients whose infrastructure management skills are lacking, and they are making a mess of things.
While serverless infrastructures certainly eliminate a range of vulnerability classes, it is adoption is unlikely to be sufficient to secure platforms that are inadequate for the threats they face.
At the end of the day, someone has to put in the work to ensure that things are patched, safe, and secure, whether the computing model is serverless or not.
- insanitybit 3y ago> Reading your comments, I get the impression that you are used to dealing with clients whose infrastructure management skills are lacking, and they are making a mess of things. I mean, I worked at Datadog when this happened: https://www.datadoghq.com/blog/engineering/2023-03-08-deep-dive-into-platform-level-impact/ https://www.datadoghq.com/blog/engineering/2023-03-08-deep-d... Multi-day outage because of an apt update. Not the only one I've seen, and it's by no means the only issue that occurs with patching (extremely common that companies don't even know if they're patched for a given vuln).