Well, it's just an AWS Account ID
mail.cloudsecurity.club
mail.cloudsecurity.club
So if a company has a user for every dev with username first.last, you could list all devs just by knowing the Account ID?
Maybe the author misunderstood what “enumerate” means and meant to say that you can check if a given IAM entity exists under the account? Enumeration and bruteforce are very different things.
It's still a form of enumeration.
Once you know the generation scheme, you can always enumerate some form, perfect or otherwise.
If your forgot password page takes longer to respond when an account exists when it does not, it is also a side-channel attack.
This bypasses what you've mentioned.
The frobnicator service can get a database account name frobnicator_znwxhs1xehhoy. You can use a table name like accounts_c4acou45cbkre if you want.
Fun story: I worked with a DBA who used nearly random table and field names - nonstandard abbreviations, unnatural reordering, weirds prefixes and suffixes. He didn't do it for security purposes though - he wanted us devs to always depend on him to decode those newly-added tables and fields. Although he wasn't busy (you can always see him browse eBay for Oakley sunglasses and investing in expensive Costco wines he would later sell when the price peaks - he wasn't a drinker himself), when we wanted to ask him about a field or table or beg him to write a stored procedure, he would start checking his calendar and schedule a 30-minute or 1-hour meeting at least a week in the future, often 2 or 3, and he managed to discipline us to stop asking why so further in the future by making scenes regarding how busy he is! He also persuaded our CEO to buy the super expensive ERwin (an ERD modeler), and we were getting rejecting on Visio and other products at the same time. The early 2000s were fun times!
I'd think of it as more a defence in depth measure. It's not a secret, but taking some common sense steps to not spray it all over the place could slow down an attacker, and a lot of the time just making yourself a slightly harder target than the next guy is enough that an attacker will go in search of softer targets.
> Here's my take: The Account ID is useless and not a direct weakness.
I figured it must be AI-generated slop, and closed the window.