34 ms·
Long lived credentials are a security red flag. We setup our AWS organization’s policies (SCPs) to prohibit long-lived tokens. Instead access goes through SSO
by ali_piccioni 2y ago
Long lived credentials are a security red flag.
We setup our AWS organization’s policies (SCPs) to prohibit long-lived tokens. Instead access goes through SSO or OIDC.
It’s difficult to track usage behind access tokens, prevent leaks, and effectively revoke them.
- specialist 2y agoYup. TTL (leases) must become the norm for All The Things.