Hacker News new | ask | show | jobs
by Bridgexapi 54 days ago
one thing that always felt off to me is how much focus goes into how access is granted and rotated, and much less into what actually happens after that access is used

even with short-lived or well-scoped credentials, the behavior behind them can still be pretty opaque depending on the system

so you reduce risk on access, but what happens after can still be hard to reason about or observe