Viewing profile — nutbear
nutbear
HN member- Joined
- Wed, Dec 05, 2018, 6:03 AM UTC
- HN karma
- 8
- Public activity
- 14 items
- HN profile
- View on Hacker News ↗
About nutbear
No profile information was provided.
Recent public activity
-
comment
Comment #48120919
[dead]
- story
-
comment
Comment #38521505
Good catch on the bucket vs object level permissions with S3 and s3:PutObject. I'd also be curious for future plans with resource policies as that's another layer of complexity to …
-
comment
Comment #38520194
Yes. Good points. Agreed with patchwork as sometimes IAM can take a backseat to different priorities such as application development or feature development. There's a couple differ…
-
comment
Comment #38519160
IAM Policies in AWS are inherently difficult - there's a lot of nuance to the policies such as evaluation logic (allow/deny decisions), resource scoping, conditionals, and more. It…
-
comment
Comment #35503988
I wrote a blog detailing what this change means on S3 ACLs and Block Public Access on by default: https://www.cloudquery.io/blog/finding-enabled-s3-acls-and-d...
- comment
- story
- story
-
comment
Comment #34586761
We wrote a post on this and some of the nuances/discrepancies for these S3 settings: https://www.cloudquery.io/blog/finding-enabled-s3-acls-and-d...
-
comment
Comment #32154749
Thanks for sharing your story! A decent amount of disclosure programs explicitly call out social engineering as unacceptable conduct and submissions. However, social engineering is…
- story
- comment
- story