Hacker News new | ask | show | jobs
by cle 1615 days ago
That definitely sounds plausible. AWS services undergo mandatory security reviews and threat modelling that usually cover these scenarios exhaustively. A lot of work and complexity goes into scoping down credentials for defense-in-depth protection, to protect against exactly these kinds of issues.