Hacker News new | ask | show | jobs
by guywhocodes 1949 days ago
Working currently with a cloudsecurity project, the sheer amount of surface area that AWS exposes combined with the amount of asterisks I see in various types of policies is terrifying. Enumeration is incredibly dangerous when there are so many poor service roles blindly trusting an entire AWS service, not realizing this is trust across accounts.