<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: bnchandrapal</title><link>https://news.ycombinator.com/user?id=bnchandrapal</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 28 Apr 2026 21:20:39 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=bnchandrapal" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[How 'What Can Go Wrong?' Went Wrong]]></title><description><![CDATA[
<p>Article URL: <a href="https://badshah.io/what-can-go-wrong-went-wrong/">https://badshah.io/what-can-go-wrong-went-wrong/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46227025">https://news.ycombinator.com/item?id=46227025</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 11 Dec 2025 02:42:53 +0000</pubDate><link>https://badshah.io/what-can-go-wrong-went-wrong/</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=46227025</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46227025</guid></item><item><title><![CDATA[New comment by bnchandrapal in "How not to get locked out of your AWS account"]]></title><description><![CDATA[
<p>TL;DR: Add MFA to AWS root user. If you don't have MFA with root AND your email server of root email is hosted in same AWS account, it gets tricky to recover.<p>Sidenote, I was shocked to see "There was an AWS keypair saved in the CI secrets that hadn't been used since 2022."</p>
]]></description><pubDate>Mon, 26 May 2025 05:08:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=44094146</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=44094146</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44094146</guid></item><item><title><![CDATA[AWS Product Lifecycle: End of Life Information]]></title><description><![CDATA[
<p>Article URL: <a href="https://aws.amazon.com/products/lifecycle/">https://aws.amazon.com/products/lifecycle/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44082022">https://news.ycombinator.com/item?id=44082022</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 24 May 2025 16:17:20 +0000</pubDate><link>https://aws.amazon.com/products/lifecycle/</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=44082022</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44082022</guid></item><item><title><![CDATA[Setting Up a Cloud Security Roadmap for Your Startup]]></title><description><![CDATA[
<p>Article URL: <a href="https://awssecuritydigest.com/articles/cloud-security-roadmap-for-startups">https://awssecuritydigest.com/articles/cloud-security-roadmap-for-startups</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44079779">https://news.ycombinator.com/item?id=44079779</a></p>
<p>Points: 4</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 24 May 2025 08:57:16 +0000</pubDate><link>https://awssecuritydigest.com/articles/cloud-security-roadmap-for-startups</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=44079779</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44079779</guid></item><item><title><![CDATA[Tailpipe – open-source SIEM for instant log insights, powered by DuckDB]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/turbot/tailpipe">https://github.com/turbot/tailpipe</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=42898103">https://news.ycombinator.com/item?id=42898103</a></p>
<p>Points: 5</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 01 Feb 2025 13:23:50 +0000</pubDate><link>https://github.com/turbot/tailpipe</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=42898103</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42898103</guid></item><item><title><![CDATA[New comment by bnchandrapal in "Well, it's just an AWS Account ID"]]></title><description><![CDATA[
<p>Yes, you're right. Reading my statement in hindsight shows thats not correct. My intention was to convey that you can check for the existence of common IAM users and roles in the accounts (and even existence of company specific entities like users with first.last pattern, product names, etc)
I've slightly updated the point a bit.</p>
]]></description><pubDate>Wed, 10 Jul 2024 04:31:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=40923721</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=40923721</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40923721</guid></item><item><title><![CDATA[Well, it's just an AWS Account ID]]></title><description><![CDATA[
<p>Article URL: <a href="https://mail.cloudsecurity.club/p/well-just-aws-account-id">https://mail.cloudsecurity.club/p/well-just-aws-account-id</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=40923188">https://news.ycombinator.com/item?id=40923188</a></p>
<p>Points: 106</p>
<p># Comments: 33</p>
]]></description><pubDate>Wed, 10 Jul 2024 02:21:30 +0000</pubDate><link>https://mail.cloudsecurity.club/p/well-just-aws-account-id</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=40923188</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40923188</guid></item><item><title><![CDATA[New comment by bnchandrapal in "Ask HN: Could you share your personal blog here?"]]></title><description><![CDATA[
<p><a href="https://badshah.io/" rel="nofollow noreferrer">https://badshah.io/</a><p>Blog posts on Cloud Security, DevSecOps and other personal experiments+experiences in security<p>RSS: <a href="https://badshah.io/index.xml" rel="nofollow noreferrer">https://badshah.io/index.xml</a></p>
]]></description><pubDate>Thu, 06 Jul 2023 02:49:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=36610460</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=36610460</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36610460</guid></item><item><title><![CDATA[My Love/Hate Relationship with Cloud Custodian]]></title><description><![CDATA[
<p>Article URL: <a href="https://badshah.io/my-love-hate-relationship-with-cloud-custodian/">https://badshah.io/my-love-hate-relationship-with-cloud-custodian/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=35513278">https://news.ycombinator.com/item?id=35513278</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 10 Apr 2023 15:11:41 +0000</pubDate><link>https://badshah.io/my-love-hate-relationship-with-cloud-custodian/</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=35513278</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35513278</guid></item><item><title><![CDATA[One important feature that Dependabot is missing]]></title><description><![CDATA[
<p>Article URL: <a href="https://badshah.io/important-dependabot-feature/">https://badshah.io/important-dependabot-feature/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=33942179">https://news.ycombinator.com/item?id=33942179</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 11 Dec 2022 11:07:27 +0000</pubDate><link>https://badshah.io/important-dependabot-feature/</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=33942179</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33942179</guid></item><item><title><![CDATA[Automating Cloud Security – AWS Edition (Workshop Slides) [pdf]]]></title><description><![CDATA[
<p>Article URL: <a href="https://badshah.io/talks/slides/2022-10-12-Automating-Cloud-Security-AWS.pdf">https://badshah.io/talks/slides/2022-10-12-Automating-Cloud-Security-AWS.pdf</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=33572329">https://news.ycombinator.com/item?id=33572329</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 12 Nov 2022 12:08:50 +0000</pubDate><link>https://badshah.io/talks/slides/2022-10-12-Automating-Cloud-Security-AWS.pdf</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=33572329</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33572329</guid></item><item><title><![CDATA[Did you completely remove secrets from Git repository? Really?]]></title><description><![CDATA[
<p>Article URL: <a href="https://badshah.io/remove-secrets-from-git-repo/">https://badshah.io/remove-secrets-from-git-repo/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=33124204">https://news.ycombinator.com/item?id=33124204</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 07 Oct 2022 17:15:01 +0000</pubDate><link>https://badshah.io/remove-secrets-from-git-repo/</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=33124204</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33124204</guid></item><item><title><![CDATA[New comment by bnchandrapal in "AWS GuardDuty – the Good, the Bad, and the Ugly"]]></title><description><![CDATA[
<p>Ahhh. AWS Control tower has not cost but it requires AWS Config to be enabled. Config is yet another AWS service that can get costly over time (if continuous monitoring of changes is enabled)</p>
]]></description><pubDate>Mon, 15 Aug 2022 15:14:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=32470742</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=32470742</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32470742</guid></item><item><title><![CDATA[New comment by bnchandrapal in "AWS GuardDuty – the Good, the Bad, and the Ugly"]]></title><description><![CDATA[
<p>Out of curiosity, did you have any data lakes on S3? Did you find optimization techniques for the same?</p>
]]></description><pubDate>Mon, 15 Aug 2022 06:16:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=32466425</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=32466425</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32466425</guid></item><item><title><![CDATA[New comment by bnchandrapal in "AWS GuardDuty – the Good, the Bad, and the Ugly"]]></title><description><![CDATA[
<p>There are a few AWS security services which are free/priced reasonably.<p>Some free services:<p>1. AWS Org (Disable services and enforce guardrails)<p>2. VPC (Create private networks)<p>3. IAM (User access and IAM policy analyzer to help with least priv)<p>4. IAM Access Analyzer (Alert on resources with cross account & public access)<p>5. SSM Inventory & Patch manager (Basic check if all VMs have security updates installed)<p>Reasonably priced IMO:<p>1. AWS WAF with free managed rules (when rightly configured you get lesser FP and high ROI)</p>
]]></description><pubDate>Mon, 15 Aug 2022 04:18:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=32465850</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=32465850</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32465850</guid></item><item><title><![CDATA[AWS GuardDuty – the Good, the Bad, and the Ugly]]></title><description><![CDATA[
<p>Article URL: <a href="https://badshah.io/guardduty-good-bad-ugly/">https://badshah.io/guardduty-good-bad-ugly/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=32465516">https://news.ycombinator.com/item?id=32465516</a></p>
<p>Points: 132</p>
<p># Comments: 56</p>
]]></description><pubDate>Mon, 15 Aug 2022 03:25:59 +0000</pubDate><link>https://badshah.io/guardduty-good-bad-ugly/</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=32465516</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32465516</guid></item><item><title><![CDATA[What should you use – CloudQuery or Steampipe?]]></title><description><![CDATA[
<p>Article URL: <a href="https://badshah.io/cloudquery-vs-steampipe/">https://badshah.io/cloudquery-vs-steampipe/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=32279187">https://news.ycombinator.com/item?id=32279187</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 29 Jul 2022 16:46:02 +0000</pubDate><link>https://badshah.io/cloudquery-vs-steampipe/</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=32279187</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32279187</guid></item><item><title><![CDATA[Things I wish I knew about AWS WAF – Bot Control]]></title><description><![CDATA[
<p>Article URL: <a href="https://badshah.io/things-i-wish-i-knew-aws-waf-bot-control/">https://badshah.io/things-i-wish-i-knew-aws-waf-bot-control/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=32064155">https://news.ycombinator.com/item?id=32064155</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 12 Jul 2022 00:42:36 +0000</pubDate><link>https://badshah.io/things-i-wish-i-knew-aws-waf-bot-control/</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=32064155</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32064155</guid></item><item><title><![CDATA[What's happening in the Burp-verse – Issue #11]]></title><description><![CDATA[
<p>Article URL: <a href="https://newsletter.burpsuite.guide/issues/what-s-happening-in-the-burp-verse-issue-11-1136145">https://newsletter.burpsuite.guide/issues/what-s-happening-in-the-burp-verse-issue-11-1136145</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=31385985">https://news.ycombinator.com/item?id=31385985</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 15 May 2022 07:49:09 +0000</pubDate><link>https://newsletter.burpsuite.guide/issues/what-s-happening-in-the-burp-verse-issue-11-1136145</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=31385985</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31385985</guid></item><item><title><![CDATA[WordPress Plugin Confusion: How an update can get you pwned]]></title><description><![CDATA[
<p>Article URL: <a href="https://vavkamil.cz/2021/11/25/wordpress-plugin-confusion-update-can-get-you-pwned/">https://vavkamil.cz/2021/11/25/wordpress-plugin-confusion-update-can-get-you-pwned/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=29340903">https://news.ycombinator.com/item?id=29340903</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 25 Nov 2021 12:49:24 +0000</pubDate><link>https://vavkamil.cz/2021/11/25/wordpress-plugin-confusion-update-can-get-you-pwned/</link><dc:creator>bnchandrapal</dc:creator><comments>https://news.ycombinator.com/item?id=29340903</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=29340903</guid></item></channel></rss>