HNHacker News
TopNewBestAskShowJobs

mishappen

2 karma · joined September 16, 2019

submissionscomments
mishappen··on 'Reconciliation is dead': Indigenous Australians vow silence as referendum fails
This isn’t a good description of the proposed changes at all. Here is the entirety of the change:

— In recognition of Aboriginal and Torres Strait Islander peoples as the First Peoples of Australia:

1. there shall be a body, to be called the Aboriginal and Torres Strait Islander Voice; 2. the Aboriginal and Torres Strait Islander Voice may make representations to the Parliament and the Executive Government of the Commonwealth on matters relating to Aboriginal and Torres Strait Islander peoples; 3. the Parliament shall, subject to this Constitution, have power to make laws with respect to matters relating to the Aboriginal and Torres Strait Islander Voice, including its composition, functions, powers and procedures. —

To summarise, it’s an advisory body that can make non-binding representations to government on issues relating to Aboriginal and Torres Strait Islander peoples. It is also exclusively a federal government body. On top of this, that same federal government controls everything about this advisory body (composition, functions, powers and procedures).

mishappen··on AWS Session Manager: less infrastructure, more features
It looks like the docs were update in June 2019 (https://github.com/awsdocs/aws-systems-manager-user-guide/co...)
mishappen··on AWS Session Manager: less infrastructure, more features
Thanks for clarifying, I didn’t recheck since we rolled out SSM in mid-2019 and then scrambled when we realised we’d granted account wide S3 permissions. The article I linked to also has a recommended minimal IAM policy for Run Command and SSM. I’ll update my comment to mention this.
mishappen··on AWS Session Manager: less infrastructure, more features
Be careful with SSM in general. The documentation suggests adding the AmazonEC2RoleforSSM policy to the role of the EC2 instances you want to access via Session Manager. This role grants read/write to all S3 buckets in your account (amongst other things). See this article for better steps and unavoidable risky things: https://cloudonaut.io/aws-ssm-is-a-trojan-horse-fix-it-now/