Also a big one that the author forgot to mention; because server-less back-ends are shared by many companies, there is a stronger incentive for hackers to try to hack the provider.
Serverless security implications from infra to OWASP
11–16 of 16 posts
Re: Serverless security implications from infra to OWASP
#12Also a big one that the author forgot to mention; because server-less back-ends are shared by many companies, there is a stronger incentive for hackers to try to hack the provider.
I'm really quite astounded that there haven't been more huge cloud hacks. I guess hypervisor authors and cloud providers have taken security seriously enough.
For example, a state-level actor can afford to train and place operatives into an AWS-scale organization with enough access to infiltrate and undermine the system.
Re: Serverless security implications from infra to OWASP
#13Also a big one that the author forgot to mention; because server-less back-ends are shared by many companies, there is a stronger incentive for hackers to try to hack the provider.
I'm really quite astounded that there haven't been more huge cloud hacks. I guess hypervisor authors and cloud providers have taken security seriously enough.
Re: Serverless security implications from infra to OWASP
#14Re: Serverless security implications from infra to OWASP
#15Earlier quoted context omitted.
I'm really quite astounded that there haven't been more huge cloud hacks. I guess hypervisor authors and cloud providers have taken security seriously enough.
The existence of hypervisor rootkits and the vast scale of cloud provider operations argue for caution. For example, a state-level actor can afford to train and place operatives into an AWS-scale organization with enough access to infiltrate and undermine the system.
Re: Serverless security implications from infra to OWASP
#16Also a big one that the author forgot to mention; because server-less back-ends are shared by many companies, there is a stronger incentive for hackers to try to hack the provider.
I'm really quite astounded that there haven't been more huge cloud hacks. I guess hypervisor authors and cloud providers have taken security seriously enough.
(This doesn't rule out paying a lot of attention to security, of course).