Live data from Hacker News

Cleaning Up Dead Bodies in AWS IAM

noq.dev

11–20 of 69 posts

Re: Cleaning Up Dead Bodies in AWS IAM

#11
post #8

>Discover why conventional CSPM/CIEM tools fall short in cleaning up AWS IAM, and explore a better solution with Noq and IAMbic We live in a noun hell where every technical topic has a high barrier to entry that makes it hard to casually learn anything. It's difficult to be even a traditional generalist in this ecosystem, and yet the market treats people as if the only way to be considered valuable is to be a super g…

Acronyms are the worst. I guess people do it to sound cool or something, but I once maintained a legacy project that had an acronym for a name. Not a single person working at the entire company knew what the acronym originally meant, and of course, it was never documented.

Analyst firms (ie Gartner) are a big driver of this too. Couple that with the start up / VC model which needs to create new 'categories' to demonstrate differentiation, and you have a total mess.

Re: Cleaning Up Dead Bodies in AWS IAM

#12
post #8

>Discover why conventional CSPM/CIEM tools fall short in cleaning up AWS IAM, and explore a better solution with Noq and IAMbic We live in a noun hell where every technical topic has a high barrier to entry that makes it hard to casually learn anything. It's difficult to be even a traditional generalist in this ecosystem, and yet the market treats people as if the only way to be considered valuable is to be a super g…

Acronyms are the worst. I guess people do it to sound cool or something, but I once maintained a legacy project that had an acronym for a name. Not a single person working at the entire company knew what the acronym originally meant, and of course, it was never documented.

Acronyms are no different from words, in this regard. How many people remember/know why your storage is called a drive? A computer used to be a person. Why is the company Stripe named that?

Then there are backronyms and names that used to be acronyms, but technically aren't anymore.

Re: Cleaning Up Dead Bodies in AWS IAM

#13
post #4

Earlier quoted context omitted.

Can you share what the high-level goal of the project was? i.e. was the VP trying to reduce risk? scale out responsibility for managing access?

This is the sort of ladder-climbing VP behavior you see from someone who is too concerned about avoiding failures that they don't actually do anything productive. Don't launch any projects in a firm direction because if they fail, it's a failure of commission. Wastes lots of time churning what-if scenarios, blocking things & generating reports no one wants in case he gets asked for them, so he can't be accused of a f…

This comment opened my eyes in a strange way to my boss (dir of infra). This is so on the nose for how he operates it was almost painful to read.

Re: Cleaning Up Dead Bodies in AWS IAM

#14

>Discover why conventional CSPM/CIEM tools fall short in cleaning up AWS IAM, and explore a better solution with Noq and IAMbic We live in a noun hell where every technical topic has a high barrier to entry that makes it hard to casually learn anything. It's difficult to be even a traditional generalist in this ecosystem, and yet the market treats people as if the only way to be considered valuable is to be a super g…

[deleted]

Re: Cleaning Up Dead Bodies in AWS IAM

#15
post #8

>Discover why conventional CSPM/CIEM tools fall short in cleaning up AWS IAM, and explore a better solution with Noq and IAMbic We live in a noun hell where every technical topic has a high barrier to entry that makes it hard to casually learn anything. It's difficult to be even a traditional generalist in this ecosystem, and yet the market treats people as if the only way to be considered valuable is to be a super g…

Acronyms are the worst. I guess people do it to sound cool or something, but I once maintained a legacy project that had an acronym for a name. Not a single person working at the entire company knew what the acronym originally meant, and of course, it was never documented.

A long time ago I worked on a defense program called "XMS 3000", hilariously, it was explained to me that this literally did not mean anything. They needed a name and somebody came up with this to sound cool.

Re: Cleaning Up Dead Bodies in AWS IAM

#16
post #4

Earlier quoted context omitted.

Can you share what the high-level goal of the project was? i.e. was the VP trying to reduce risk? scale out responsibility for managing access?

This is the sort of ladder-climbing VP behavior you see from someone who is too concerned about avoiding failures that they don't actually do anything productive. Don't launch any projects in a firm direction because if they fail, it's a failure of commission. Wastes lots of time churning what-if scenarios, blocking things & generating reports no one wants in case he gets asked for them, so he can't be accused of a f…

“Getting shit done” is 3D chess we play to convince ourselves there is a goal when it’s just more low effort toil.

Re: Cleaning Up Dead Bodies in AWS IAM

#17
post #4

At my last company they asked me to find all the users who no longer needed access to our AWS account, as well as create a report for teams to review if each of their members needed access to the roles they have access to. It took a little bit to understand the IAM model, but I created dozens of reports for a few hundred engineers. Dead users were deleted, but literally nobody reviewed group access with the reports I…

Can you share what the high-level goal of the project was? i.e. was the VP trying to reduce risk? scale out responsibility for managing access?

I'm dealing with the same type of nonsense currently, as an internal audit team sees security groups being flagged by the scanning software that are open to 0.0.0.0/0 which is automatically "bad", even though the hosts have no public IP's and are being automatically managed by EKS to setup links to k8s NodePorts and the ELB.

Same with security groups. Gartner has some "best practice" doc somewhere, someone loads that into a security tool, the tool flags things, and these checkboxes must go from red to green. The technical hurdles to comply or actual value do not matter.

Re: Cleaning Up Dead Bodies in AWS IAM

#18
post #4

Earlier quoted context omitted.

Can you share what the high-level goal of the project was? i.e. was the VP trying to reduce risk? scale out responsibility for managing access?

Reducing risk, yes, but I think the VP just sat around thinking of project ideas that sound useful without asking around to see if relevant stakeholders are actually interested

Thanks for the additional context.

Agree that leaders should definitely be ready to motivate stakeholders and collaborating teams to act on this kind of info before spending significant time gathering & producing it.

Re: Cleaning Up Dead Bodies in AWS IAM

#19
post #10

Earlier quoted context omitted.

This is the sort of ladder-climbing VP behavior you see from someone who is too concerned about avoiding failures that they don't actually do anything productive. Don't launch any projects in a firm direction because if they fail, it's a failure of commission. Wastes lots of time churning what-if scenarios, blocking things & generating reports no one wants in case he gets asked for them, so he can't be accused of a f…

If I’ve learned anything, the only people who care about doing things are at the very, very bottom. No one up the chain actually cares about doing things. They talk about doing things, present grand slidedecks internally and at conferences about doing things, have project/product/engineering managers constantly planning on doing things and thinking about better/faster ways to do them. But really there’s an entire pyr…

You guys have it so wrong. Their job is to get you to do things. With slide decks. Presentations. Speeches. Roadmaps. Stories. Visions. Carrots. That’s their job. As well as to aggregate the litany of statuses into an über status at the end of the week/month/quarter so that their higher ups see work being done. What they do is different from what you do so you only see them not doing what you’re doing, not what they are doing. However, if we are going to generalize, yes - you are correct on the fact that they spend their time thinking about better/faster without making it better nor faster (mostly the opposite).

They have context into why you are doing something, even if you don’t.

Re: Cleaning Up Dead Bodies in AWS IAM

#20
post #16

Earlier quoted context omitted.

This is the sort of ladder-climbing VP behavior you see from someone who is too concerned about avoiding failures that they don't actually do anything productive. Don't launch any projects in a firm direction because if they fail, it's a failure of commission. Wastes lots of time churning what-if scenarios, blocking things & generating reports no one wants in case he gets asked for them, so he can't be accused of a f…

“Getting shit done” is 3D chess we play to convince ourselves there is a goal when it’s just more low effort toil.

Work is work they give me a paycheck to write code.

Rather write some code than deal with a chickenshit leader who wants 100 iterations of project plans for work we will never do or generating reports that no one will ever read.

Being paid to sit at a computer and not doing real work all day is more torturous than simply having actual tasks and work to do.

Post reply on HN