I feel like the potential to abuse this is pretty low but AWS will ‚fix’ this and make IAM even harder
As there are no “valid” IAM use cases for prefix matching on a resource id (you don’t control the resource id so you can never group resources by using a common prefix, etc) then there is no difficulty imposed by patching this.
The only question is backwards compatibility. If some idiot somewhere actually used a prefix match against a substring in production to match part of their actual resource id, this would presumably break it.
As for potential for harm, I don’t think it’s as low as you make it out to be. It’s hard to be anonymous online. This is another example of that. Forget common crawl or Carvana, and think dissident or whistleblower.