Hacker News new | ask | show | jobs
by hellomichibye 3285 days ago
Cloudtrail and config buckets should be in a separate account with no access at all (besides root) otherwise an attacker can delete the cloudtrail logs and you have no idea what he did