6 ms·
It's not reliable, and presenting it as-such shows a lack of understanding of basic security posture. Don't take my word for it, watch the news in <6 months an
by tcdent 2mo ago
It's not reliable, and presenting it as-such shows a lack of understanding of basic security posture.
Don't take my word for it, watch the news in <6 months and we'll certainly see it get bypassed.
- dewey 2mo agoMaybe that's a hot take, but it's probably still safer than how things are often done in reality when employees want to "get something done" and sign up for random services, download their own software or other variants of shadow IT.
- tcdent 2mo agoCompletely agree. This posture is applicable while we ease out of what I'm calling the "golden era" (loose restrictions on access with limited consequence) but one of the reasons I am pedantic and bearish about solutions like this is that they too have a short lifespan that we can already estimate the expiration date of.
- ChrisMarshallNY 2mo agoAren't a large number of massive data leaks caused by some Marketing person setting up an AWS instance, and dumping the corporate DB into it?
- dewey 2mo agoI wouldn't say that's a "Marketing person" failure mode, there's enough open buckets, public mongodb or Elastic instances with wrong credentials.
- ChrisMarshallNY 2mo agoFair point.