Earlier quoted context omitted.
> So Amazon could easily have tested their client on 3rd party servers and still not spotted the problem This would still be a red flag, as the service in question is their instance metadata service that provides authentication tokens. Something that important should be integration-tested with the actual service.
> This would still be a red flag, Perhaps I don't understand the issue you're discussing but how would the client working on 3rd party services be a red flag when that is the desired behavior?
Their own documentation refers to that library (or did at that point in time, not sure about now).