Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Aws credentials are short lived precisely so that leaking them has a time limited blast radius.

Automatic retrieval, instead of keeping them on disk, is what makes short lived credentials possible.



I'm not convinced that time-limiting the blast radius matters. It just means that malicious use of the credentials has to be automated, and that's a pretty damn low bar.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: