|
|
|
|
|
by fulafel
2477 days ago
|
|
This is true, AWS is pretty anti-internet in all their architecture recommendations. IMO security is better done by firewalling and protocol level authentication (belt + suspenders) because it keeps your configuration clean and understandable, and complexity is the enemy of security. The attitude has two things in AWS interest: 1) keep lock-in by encouraging customers to build AWS-internal networks 2) don't scare away the lift-and-shift customers who want to transplant their 1990s style "intranet" (or mental model, at least) onto AWS. Explains also why they aren't very keen about IPv6 because that would encourage internetworking. Just don't tell anyone that you can access the AWS console from the internet :) |
|