Hacker News new | ask | show | jobs
by rcme 1266 days ago
This only applies if the stolen credentials can’t create roles and can’t modify existing roles.
2 comments

...and don't leave a payload behind, to maintain persistent access (unless I'm missing something?)
This is a good reminder to always follow least-permission best practices.
I’d add drift detection on everything IAM / SCP / Org to this list too.

A session token with only a few minutes validity can be enough for someone to make their access permanent.