<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: DanielSlauth</title><link>https://news.ycombinator.com/user?id=DanielSlauth</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 27 Jun 2026 07:39:12 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=DanielSlauth" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by DanielSlauth in "Launch HN: Diversion (YC S22) – Cloud-Native Git Alternative"]]></title><description><![CDATA[
<p>Looks awesome!</p>
]]></description><pubDate>Mon, 22 Jan 2024 18:02:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=39092893</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=39092893</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39092893</guid></item><item><title><![CDATA[New comment by DanielSlauth in "Launch HN: Slauth (YC S22) – auto-generate secure IAM policies for AWS and GCP"]]></title><description><![CDATA[
<p>><i>I'd like to challenge you on what seems to be the main claim behind why Slauth is a necessary product: "the amount of money that is being spent on tooling to scan for IAM misconfigurations in the cloud</i>.<p>The quote you use got me to further research the market and speak to users of those toolings. From speaking to the users it was evident that the amount of misconfigurations being deployed wasn't being reduced.<p>I imagine users of cloud scanning tools would also use a pro-active tool like Slauth or any other shift-left tool that would aim at preventing as opposed to reacting.</p>
]]></description><pubDate>Tue, 05 Dec 2023 07:38:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=38528068</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=38528068</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38528068</guid></item><item><title><![CDATA[New comment by DanielSlauth in "Launch HN: Slauth (YC S22) – auto-generate secure IAM policies for AWS and GCP"]]></title><description><![CDATA[
<p>Perhaps I should have emphasized better that indeed the LLM's are trustworthy by themselves and require several extra checks. These would be policy simulators, connecting to cloud environments and running checks in Dev/Staging.<p>Again, I understand the skepticism using LLM's but currently everything is done manually and it shows that doesn't work well. So using LLM's is a quick way to improve the current situation and hopefully we can further compliment it with checks and balances</p>
]]></description><pubDate>Mon, 04 Dec 2023 14:31:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=38517701</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=38517701</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38517701</guid></item><item><title><![CDATA[New comment by DanielSlauth in "Launch HN: Slauth (YC S22) – auto-generate secure IAM policies for AWS and GCP"]]></title><description><![CDATA[
<p>I believe the minute you connect a Dev or staging environment to Slauth.io and we can run simulations and show divs we can offer pretty strong SLA's..</p>
]]></description><pubDate>Mon, 04 Dec 2023 14:28:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=38517663</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=38517663</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38517663</guid></item><item><title><![CDATA[New comment by DanielSlauth in "Launch HN: Slauth (YC S22) – auto-generate secure IAM policies for AWS and GCP"]]></title><description><![CDATA[
<p>The open-source project is a CLI you can put into your CI/CD so i think a pretty neat workflow where there should be less friction considering DevOps/security don't need to ping-pong on permissions.</p>
]]></description><pubDate>Mon, 04 Dec 2023 14:24:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=38517610</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=38517610</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38517610</guid></item><item><title><![CDATA[New comment by DanielSlauth in "Launch HN: Slauth (YC S22) – auto-generate secure IAM policies for AWS and GCP"]]></title><description><![CDATA[
<p>Thanks and let's see what Q will look like. I'm hoping the project will further evolve in integrating it in your CI/CD with PR's when commit requires IAM changes.</p>
]]></description><pubDate>Mon, 04 Dec 2023 14:21:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=38517571</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=38517571</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38517571</guid></item><item><title><![CDATA[New comment by DanielSlauth in "Launch HN: Slauth (YC S22) – auto-generate secure IAM policies for AWS and GCP"]]></title><description><![CDATA[
<p>First of all its pretty awesome your permissions are very tight. You are definitely on the other side of the spectrum compared to the rest. I get it that there is a lot of skepticism because of people hyping LLM's so indeed for now we use it as Copilot and not the driver. 
Hopefully you can agree though its pretty random that we are still manually creating IAM policies and need to get accustomed with the thousands of different permissions :)</p>
]]></description><pubDate>Mon, 04 Dec 2023 14:12:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=38517432</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=38517432</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38517432</guid></item><item><title><![CDATA[New comment by DanielSlauth in "Launch HN: Slauth (YC S22) – auto-generate secure IAM policies for AWS and GCP"]]></title><description><![CDATA[
<p>Do you think humans are doing a better job? Research shows that 95% of the permissions granted to users aren't used which creates huge problems and is a reason for spending millions in security tools. Why not use Slauth and other checks such as policy simulators to get tightened policies pre-deployed</p>
]]></description><pubDate>Mon, 04 Dec 2023 13:35:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=38516992</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=38516992</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38516992</guid></item><item><title><![CDATA[Launch HN: Slauth (YC S22) – auto-generate secure IAM policies for AWS and GCP]]></title><description><![CDATA[
<p>Hi HN, We're Daniel and Bruno and working on <a href="https://slauth.io/">https://slauth.io/</a>. Slauth.io is a CLI to auto-generate secure IAM policies for AWS, and GCP (Azure in the next few days!). We enable development teams to speed up creating secure policies and reduce over-permissive policies being deployed to the cloud.<p>Check out the video or give our open-source CLI a try with one of the sample repo's on <a href="https://github.com/slauth-io/slauth-cli">https://github.com/slauth-io/slauth-cli</a>
<a href="https://www.loom.com/share/bd02211659eb4c7f9b335e34094b57cb?sid=f5e84cb2-6939-4d7f-9ed8-90521c90f6de" rel="nofollow noreferrer">https://www.loom.com/share/bd02211659eb4c7f9b335e34094b57cb?...</a><p>We got into the cloud access market by coincidence and were amazed by the amount of money spent on IAM. Current tooling such as <a href="http://Ermetic.com" rel="nofollow noreferrer">http://Ermetic.com</a> and <a href="http://wiz.io/" rel="nofollow noreferrer">http://wiz.io/</a> visualize IAM misconfigurations post deployment but don't actually change engineering behavior, leaving organizations in a constant loop of engineers deploying over-permissive policies ⇒ security engineers/CISO's getting alerts ⇒ Jira tickets created begging developers to remediate ⇒ New over-permissive policies being deployed again.<p>We interviewed hundreds of developers and DevOps engineers and discovered two key pain points:<p>1. *IAM is a Hassle:* Developers despise dealing with IAM intricacies.
2. *Speed vs. Security:* IAM was slowing them down in deploying quality code swiftly.<p>So the objective is automate policy creation so that developers don't have to deal with it, and harden IAM security pre-deployment.<p>We employ Large Language Models (currently OpenAI GPT-4) to scan code in any language. Through a series of prompts, we identify service calls and the actions required. The resource name receives a placeholder unless its embedded in the code. We aim in the future to create a static code analyzer in order to not send any source code to LLM's but for now using LLM's is the fastest way to market and somewhat accepted by the industry through the use of Github Copilot etc.<p>You can use the CLI in the terminal or actually integrate it in your CI/CD and have it become a part of your development team workflow.<p>Three main questions we receive<p>1. *Security Concerns:* How can I trust [Slauth.io](<a href="http://slauth.io/">http://slauth.io/</a>) to access my source code?
2. *Policy Accuracy:* How can I trust [Slauth.io](<a href="http://slauth.io/">http://slauth.io/</a>) creates the right policies?
3. *Differentiation:* How are you different from IAMLive, IAMBic AccessAnalyzer or Policy Sentry?<p>To address the first concern, we don't access your code directly. Instead, we offer a CLI that integrates into your CI/CD pipeline, allowing local code scanning. <a href="http://slauth.io/">http://slauth.io/</a> uses your OpenAI key to convert the code into a secure policy, with the option to output results to *`stdout`* or a file for artifact upload and download. That does mean OpenAI has access to the source code located in the path you set to be scanned as we need to know which SDK calls are performed to generate the policies.<p>We have extensively tested it on AWS , Typescript and GPT 4 with very good results (>95% accuracy). We do know these accuracies drop when using GPT 3.5 so if possible, use GPT 4 as we are improving the prompts. GCP and Azure have been tested less but the results when using GPT 4 seem equally high. We also have experienced some hallucinations but they have not effected the outcome of a secure policy but merely the structure of how the policy is generated. That is not to say that it is 100% reliable hence we aim to provide toolings to double check policies through policy simulators and other means.<p>Compared to competitors, we focus mainly on generating secure policies pre-deployment and automating as much as possible. We were inspired by IAMLive but it wasn't as scalable to use across development teams. Policy Sentry is great for templates but with <a href="http://Slauth.io">http://Slauth.io</a> you actually get a granular least privilege policy. Lastly, access analyzer is used to harden security policies which have already been deployed which is similar to other cloud scanning tools and creates a strange reactive process to security. The new access-analyzer feature checks policy diffs in your CDK but again doesn't actually generate the policy pre-deployment.<p>We recognise some engineers are very capable of creating secure policies but similar to using Checkov and TFscan in the context of IaC deployment, we believe using Slauth.io will become a necessity in your CI/CD when deploying service permissions to make sure no IAM misconfiguration appear in the cloud.<p>Would love to get your feedback and feel free to interact on our Github repo and join our Slack community.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=38516795">https://news.ycombinator.com/item?id=38516795</a></p>
<p>Points: 122</p>
<p># Comments: 77</p>
]]></description><pubDate>Mon, 04 Dec 2023 13:10:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=38516795</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=38516795</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38516795</guid></item><item><title><![CDATA[Ask HN: IAM Policies and Early-Adaptors]]></title><description><![CDATA[
<p>Almost 6 months ago I wrote this post https://news.ycombinator.com/item?id=34038663 which was a big motivation to start building the IAM Policy Copilot.<p>We conducted a lot of interviews and honestly were confused about the best place to start. How can we best ingest data in order to generate a “least-privilege” policy. We started with integrating with Github actions to intercept traffic and generate the policies that can be used for deployments.<p>Our roadmap includes a multi-layered approach of analyzing data through traffic,  static code  and patterns/context in order to address more use-cases.<p>For now, we would love to learn from AWS partners and heavy AWS users how they currently deal with IAM and what an ideal solution would look like for them.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=36195525">https://news.ycombinator.com/item?id=36195525</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 05 Jun 2023 12:53:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=36195525</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=36195525</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36195525</guid></item><item><title><![CDATA[New comment by DanielSlauth in "Launch HN: Slauth.io (YC S22) – IAM Policy Auto-Generation"]]></title><description><![CDATA[
<p>Nice! Will work on the pricing tiers and features. 
Regardless, would love for you to test it out and we can agree on the above $150/mo for 200 policies :)</p>
]]></description><pubDate>Mon, 19 Dec 2022 09:44:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=34050231</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=34050231</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34050231</guid></item><item><title><![CDATA[New comment by DanielSlauth in "Launch HN: Slauth.io (YC S22) – IAM Policy Auto-Generation"]]></title><description><![CDATA[
<p>Thank you for the feedback!! We needed something to start of with but your arguments are very fair so we will have to change it. 
Would you like to sign up for the Beta and give it a try? Would absolutely love your opinionated feedback :D 
Also, how much would you pay? Could you give us some insights there.</p>
]]></description><pubDate>Sun, 18 Dec 2022 18:01:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=34040331</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=34040331</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34040331</guid></item><item><title><![CDATA[New comment by DanielSlauth in "Launch HN: Slauth.io (YC S22) – IAM Policy Auto-Generation"]]></title><description><![CDATA[
<p>We have found several "problems" that we think can be done better
1) CloudTrail requires to run for a duration of time before suggesting a policy which means long time until getting value. What do you do until the suggestion? Run a less secure policy?
2) CloudTrial actually doesn't log all events so we are using either AWS SDK metrics or a proxy to make sure we get all activity 
3) Integrations with Terraform, Git repository in order to make it easy to use in day to day 
4) Hopefully in the future we can extend to other cloud vendors :)</p>
]]></description><pubDate>Sun, 18 Dec 2022 17:08:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=34039702</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=34039702</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34039702</guid></item><item><title><![CDATA[New comment by DanielSlauth in "Launch HN: Slauth.io (YC S22) – IAM Policy Auto-Generation"]]></title><description><![CDATA[
<p>Thanks! Will have a look. Have you used it? If so, would love to learn what you liked and didn't like</p>
]]></description><pubDate>Sun, 18 Dec 2022 16:59:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=34039600</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=34039600</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34039600</guid></item><item><title><![CDATA[New comment by DanielSlauth in "Launch HN: Slauth.io (YC S22) – IAM Policy Auto-Generation"]]></title><description><![CDATA[
<p>Getting slower haha... HN is generating traffic but will have to ask Webflow what's going on lol</p>
]]></description><pubDate>Sun, 18 Dec 2022 16:53:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=34039539</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=34039539</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34039539</guid></item><item><title><![CDATA[New comment by DanielSlauth in "Launch HN: Slauth.io (YC S22) – IAM Policy Auto-Generation"]]></title><description><![CDATA[
<p>Thanks!! Looks really good. I hope we can contribute from a different angle by focussing on the creation of the policy and ideally expand beyond AWS :) Thanks for the heads up</p>
]]></description><pubDate>Sun, 18 Dec 2022 16:35:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=34039333</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=34039333</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34039333</guid></item><item><title><![CDATA[New comment by DanielSlauth in "Launch HN: Slauth.io (YC S22) – IAM Policy Auto-Generation"]]></title><description><![CDATA[
<p>Yes def! We wanted to quickly validate the need so started with AWS but if we get good traction we will expand to GCP next :) Feel free to share with AWS users so that we can get going :D</p>
]]></description><pubDate>Sun, 18 Dec 2022 16:21:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=34039174</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=34039174</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34039174</guid></item><item><title><![CDATA[New comment by DanielSlauth in "Launch HN: Slauth.io (YC S22) – IAM Policy Auto-Generation"]]></title><description><![CDATA[
<p>We eventually want to make this agnostic and have it work for all cloud vendors. Pretty complex to write policies if you are running multi-cloud!</p>
]]></description><pubDate>Sun, 18 Dec 2022 16:14:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=34039081</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=34039081</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34039081</guid></item><item><title><![CDATA[Launch HN: Slauth.io (YC S22) – IAM Policy Auto-Generation]]></title><description><![CDATA[
<p>Hey HN, we are Daniel and Tal, Co-founders of Slauth.io (<a href="https://www.slauth.io">https://www.slauth.io</a>). Slauth auto-generates IAM policies in order to save engineering time and make your policies more secure.<p>If you're an engineer, you probably know how tedious and error-prone it can be to manually write IAM policies. We surveyed over 70 engineers and found out that a majority are using or have used wildcards (*) in order to quickly write IAM policies.<p>By using client-side monitoring or via a proxy, Slauth.io observes all of the API activity and generates a policy based on functionality and least privileges.<p>Once deployed in a remote environment, or run locally, you will need to run an end-to-end test using a wildcard policy. Slauth will observe the activity, apply its logic based on large amounts of behavioral patterns of the service you deploy, and create a high quality IAM policy.<p>The IAM policy will be presented through the Slauth Dashboard where it can be copy/pasted or as a pull-request into your Git repository ready to be reviewed. Integrations with IaC services such as Terraform are also available.<p>Our objective is to automate manual error-prone IAM policy writing in order to increase engineering velocity, reduce friction and harden security.<p>Would love your feedback on the value proposition and if you would use the AWS SDK or Slauth proxy for onboarding.<p>Feel free to also sign up for Beta usage! <a href="https://www.slauth.io">https://www.slauth.io</a></p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=34038663">https://news.ycombinator.com/item?id=34038663</a></p>
<p>Points: 63</p>
<p># Comments: 32</p>
]]></description><pubDate>Sun, 18 Dec 2022 15:39:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=34038663</link><dc:creator>DanielSlauth</dc:creator><comments>https://news.ycombinator.com/item?id=34038663</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34038663</guid></item></channel></rss>