HNHacker News
TopNewBestAskShowJobs

MiguelHzBz

142 karma · joined October 13, 2021

security researcher that learns and internalizes new concepts and skills continuously. He spent the last 6 years at big tech companies working with small teams in research area with great versatility in addition to seeking own projects. Speaker at several cyber-security conferences
submissionscomments
MiguelHzBz··on Ask HN: Why is so hard to apply the least privilege principle in IAM accounts?
IMO, there is no simple answer, since many access control elements are involved and implementations vary between organizations.

From my experience I would say that there may be different factors:

- Every developer is an exception

- IAM is challenging to scale

- Lazy IT Teams?

- Visibility of access controls are poor

Some useful references:

- https://sysdig.com/blog/identity-access-management-difficult...

- https://www.effectiveiam.com/why-aws-iam-is-so-hard-to-use

- https://aws.amazon.com/blogs/security/iam-access-analyzer-ma...

MiguelHzBz··on Secure SSH on EC2: What are the real threats?
That's the point of the article. If you have the default EC2 configuration, exposed SSH is not such a critical issue. That might be simple, but sometimes we follow best practices without understanding why we follow them.