AWS Built a Security Tool. It Introduced a Security Risk
token.security
AWS Built a Security Tool. It Introduced a Security Risk
1–10 of 85 posts
Re: AWS Built a Security Tool. It Introduced a Security Risk
#2Re: AWS Built a Security Tool. It Introduced a Security Risk
#3Re: AWS Built a Security Tool. It Introduced a Security Risk
#4Someone invented the two-sentence clickline. Now even blogs do it.
Re: AWS Built a Security Tool. It Introduced a Security Risk
#5It also blew my mind that Google Cloud VPCs and autoscaling groups are global, so that you don’t have to jump through hoops and use the Global Accelerator service to architect a global application.
After learning just those two things I’m downright shocked that Google is still in 3rd place in this market. AWS could really use a refactor at this point.
Re: AWS Built a Security Tool. It Introduced a Security Risk
#6Re: AWS Built a Security Tool. It Introduced a Security Risk
#7Listing metadata is hardly a security issue. The entire reason these List* APIs are distinct from Get* APIs is that they don’t give you access to the object itself, just metadata. And if you’re storing secret information in your bucket names, you have bigger problems.
Re: AWS Built a Security Tool. It Introduced a Security Risk
#8As an AWS-focused practitioner, I started doing Google Cloud training and it blew my mind when I found out that the multiple account sub-account mess that AWS continues to use just doesn’t exist there. GCP sensibly uses a folder and project system that provides a lot of flexibility and IAM control. It also blew my mind that Google Cloud VPCs and autoscaling groups are global, so that you don’t have to jump through ho…
I read a lot of horror stories of people getting in troubles with GCP and not being able to talk to a human person, whereas you would get access to some human presence with AWS.
Things might have been changed, but I guess a lot of people have still this in the back of their mind.
Re: AWS Built a Security Tool. It Introduced a Security Risk
#9As an AWS-focused practitioner, I started doing Google Cloud training and it blew my mind when I found out that the multiple account sub-account mess that AWS continues to use just doesn’t exist there. GCP sensibly uses a folder and project system that provides a lot of flexibility and IAM control. It also blew my mind that Google Cloud VPCs and autoscaling groups are global, so that you don’t have to jump through ho…
"Yes accounts is a mess but they're what we have".