6 ms·
>The fact that AWS does not consider the ID a secret means that your company never should either. You and gp are talking past each other. Your focus is on Acc
by jasode 3y ago
>The fact that AWS does not consider the ID a secret means that your company never should either.
You and gp are talking past each other.
Your focus is on Account ID being public should not be a security vulnerability.
Instead, the gp's focus is on metadata leakage of identity.
Same type of conversation that differentiates concepts of "public key" vs "published key" of SSH keys:
https://news.ycombinator.com/item?id=29209312 https://news.ycombinator.com/item?id=29209312