Hacker News new | ask | show | jobs
by Artemis2 2842 days ago
I cannot overstate how much I despise these “helpful” cloud agents. They are useful for experimentation to update user accounts (SSH keys, etc. — GCP uses for its web shell as well), but they are a nightmare for production use. They are a very straightforward path from cloud account compromise to instance takeover.

Azure pulls the same trick. AWS seems fine.