|
|
|
|
|
by lijok
931 days ago
|
|
> Research shows that 95% of the permissions granted to users aren't used These would be the "s3:*" and "Resources: *" scoped permissions I assume? I can't imagine users are explicitly typing out permissions, 95% of which are not relevant for the task. > which creates huge problems Such as? What is the material impact of a workflow or a user having too many permissions? > and is a reason for spending millions in security tools Are you claiming that overscoped IAM permissions alone are responsible for 1M+ security tooling bills in companies? Would you be willing to share information on which tools these are? |
|
Security obviously https://en.wikipedia.org/wiki/Principle_of_least_privilege