3 ms·
Is AWS security boundary the AWS account? Are you expecting Vercel to provision and manage an AWS account per user? That doesn’t make any sense man, though make
by eddythompson80 6mo ago
Is AWS security boundary the AWS account? Are you expecting Vercel to provision and manage an AWS account per user? That doesn’t make any sense man, though makes sense if you’re a former AWS employee.
- raw_anon_1111 6mo agoYes the security boundary is the AWS account. It doesn’t make sense for a random employee who mistakenly uses a third party app to compromise all of its users it’s a poor security architecture. It’s about as insecure as having one Apache Server serving multiple customer’s accounts. No one who is concerned about security should ever use Vercel.
- eddythompson80 6mo ago> It’s about as insecure as having one Apache Server serving multiple customer’s accounts. You really have no clue what you’re talking about don’t you? Were you a sales guy at AWS or something?
- raw_anon_1111 6mo agoWell, I know that you have never heard of someone using a third party SaaS product at any major cloud provider compromising all of their customers accounts. Are you really defending Vercel as a hosting platform that anyone should take seriously?
- eddythompson80 6mo agoHow is any of that a defense of Vercel? If you understood how any of this works you’d know that it isn’t. Vercel is a manifestation of what’s wrong with web development, yet it has nothing to do with “creating an AWS account per user account” nor “running a reverse proxy process per user account”.
- raw_anon_1111 6mo agoBecause the same “web development” done with v0, downloaded, put in a Docker container, deployed to Lambda, with fine grain access control on the attached IAM role (all of which I’ve done) wouldn’t have that problem. Oh and I never download random npm packages to my computer. I build and run everything locally within Docker containers It has absolutely nothing to do with “the modern state of web development”, it’s a piss poor security posture. Again, I know how the big boys do this…
- otterley 6mo agoHey, knock it off. If you disagree with someone, present a substantive counterargument.
- eddythompson80 6mo agoAlready did. There is no fixing a pretender. Someone arguing akin to “the security boundary of a Linux system is the electrical strip”
- icedchai 6mo agoHe works for an AWS consulting company, where they promote cloud native solutions, driving cloud spend towards AWS. In many cases, managed cloud services are actually the way to go. However, to say that serving multiple customers with Apache is "insecure" is inaccurate. There are ways to run virtual hosts under different user IDs, providing isolation using more traditional Unix techniques.
- raw_anon_1111 6mo agoNo, if they said they were running on separate VMs I wouldn’t have any issues. Absolutely no serious company would run their web software on a shared Apache server with other tenants. How did that shared hosting work out for Vercel?
- icedchai 6mo agoAs always, "it depends" on the application. So I've worked for several B2B SaaS companies. None of them used a VM per tenant. In some cases, we used a database (schema...) or DB cluster per tenant. I've read about the Vercel incident. Given the timeline (22 months?!), it sounds like they had other issues well beyond shared hosting.
- scarface_74 6mo agoThere is a difference between a SaaS offer where you are running your code and serving multiple customers on one server/set of servers and running random customer code like Vercel.
- icedchai 6mo agoI know. I just don't think code isolation was their only issue. I've read about the incident.