<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: nutbear</title><link>https://news.ycombinator.com/user?id=nutbear</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 27 Jun 2026 08:54:50 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=nutbear" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[Authorization Bypass in AWS's Agentic AI for Enterprise: Amazon Quick]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.fogsecurity.io/blog/authorization-bypass-in-amazon-quick-ai-agents">https://www.fogsecurity.io/blog/authorization-bypass-in-amazon-quick-ai-agents</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48120918">https://news.ycombinator.com/item?id=48120918</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 13 May 2026 12:14:57 +0000</pubDate><link>https://www.fogsecurity.io/blog/authorization-bypass-in-amazon-quick-ai-agents</link><dc:creator>nutbear</dc:creator><comments>https://news.ycombinator.com/item?id=48120918</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48120918</guid></item><item><title><![CDATA[New comment by nutbear in "Launch HN: Slauth (YC S22) – auto-generate secure IAM policies for AWS and GCP"]]></title><description><![CDATA[
<p>Good catch on the bucket vs object level permissions with S3 and s3:PutObject.<p>I'd also be curious for future plans with resource policies as that's another layer of complexity to manage - where the resource policy would manage access to potentially many applications -> 1 resource.  Vs 1 application -> many resources which I think is the use case Slauth is solving for initially.<p>Confused Deputy would be interesting, could be done via Condition Keys such as SourceArn and SourceAccount, but gets complex for cross-account use cases.</p>
]]></description><pubDate>Mon, 04 Dec 2023 19:00:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=38521505</link><dc:creator>nutbear</dc:creator><comments>https://news.ycombinator.com/item?id=38521505</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38521505</guid></item><item><title><![CDATA[New comment by nutbear in "Launch HN: Slauth (YC S22) – auto-generate secure IAM policies for AWS and GCP"]]></title><description><![CDATA[
<p>Yes. Good points.  Agreed with patchwork as sometimes IAM can take a backseat to different priorities such as application development or feature development.<p>There's a couple different models for IAM ownership.  At some places, the application teams own IAM along with the application.  Sometimes, it's owned by central teams (such as security).<p>And agreed, with companies growing and changing, ownership changes as well.<p>Those factors can all complicated IAM development and policy maintenance as it becomes more difficult to find the right fit for IAM to application.  For that, it would require someone who knows exactly what the application needs access to and the IAM actions taken as well as how to configure IAM.</p>
]]></description><pubDate>Mon, 04 Dec 2023 17:30:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=38520194</link><dc:creator>nutbear</dc:creator><comments>https://news.ycombinator.com/item?id=38520194</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38520194</guid></item><item><title><![CDATA[New comment by nutbear in "Launch HN: Slauth (YC S22) – auto-generate secure IAM policies for AWS and GCP"]]></title><description><![CDATA[
<p>IAM Policies in AWS are inherently difficult - there's a lot of nuance to the policies such as evaluation logic (allow/deny decisions), resource scoping, conditionals, and more. It's often more straightforward to start with a broad IAM policy and then leave it without reducing privilege as to not adversely impact the application. Proper IAM also takes dev cycles, and may not be top priority to get a policy correct.
I think it's rare to find a 100% properly scoped IAM policy for an application.<p>Datadog recently did a State of Cloud Security and one of their findings in <a href="https://www.datadoghq.com/state-of-cloud-security/" rel="nofollow noreferrer">https://www.datadoghq.com/state-of-cloud-security/</a> is that a substantial portion of cloud workloads are excessively privileged (with more data points there).</p>
]]></description><pubDate>Mon, 04 Dec 2023 16:20:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=38519160</link><dc:creator>nutbear</dc:creator><comments>https://news.ycombinator.com/item?id=38519160</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38519160</guid></item><item><title><![CDATA[New comment by nutbear in "AWS S3 beginning to apply 2 security best practices all new buckets by default"]]></title><description><![CDATA[
<p>I wrote a blog detailing what this change means on S3 ACLs and Block Public Access on by default: <a href="https://www.cloudquery.io/blog/finding-enabled-s3-acls-and-disabled-s3-block-public-access" rel="nofollow">https://www.cloudquery.io/blog/finding-enabled-s3-acls-and-d...</a></p>
]]></description><pubDate>Sun, 09 Apr 2023 16:05:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=35503988</link><dc:creator>nutbear</dc:creator><comments>https://news.ycombinator.com/item?id=35503988</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35503988</guid></item><item><title><![CDATA[Cisco Announces Intent to Acquire Lightspin (Cloud Security)]]></title><description><![CDATA[
<p>Article URL: <a href="https://blogs.cisco.com/news/blogs-cisco-com-news-cisco-announces-its-intent-to-acquire-cloud-security-software-company">https://blogs.cisco.com/news/blogs-cisco-com-news-cisco-announces-its-intent-to-acquire-cloud-security-software-company</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=35360069">https://news.ycombinator.com/item?id=35360069</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 29 Mar 2023 17:03:56 +0000</pubDate><link>https://blogs.cisco.com/news/blogs-cisco-com-news-cisco-announces-its-intent-to-acquire-cloud-security-software-company</link><dc:creator>nutbear</dc:creator><comments>https://news.ycombinator.com/item?id=35360069</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35360069</guid></item><item><title><![CDATA[Outdated by Default: AWS IAM Policy Language Version and Legacy Evaluation Logic]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.cloudquery.io/blog/outdated-aws-iam-policy-language">https://www.cloudquery.io/blog/outdated-aws-iam-policy-language</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=34823881">https://news.ycombinator.com/item?id=34823881</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 16 Feb 2023 19:01:16 +0000</pubDate><link>https://www.cloudquery.io/blog/outdated-aws-iam-policy-language</link><dc:creator>nutbear</dc:creator><comments>https://news.ycombinator.com/item?id=34823881</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34823881</guid></item><item><title><![CDATA[New comment by nutbear in "S3 will automatically block public access and disable ACL for new buckets"]]></title><description><![CDATA[
<p>We wrote a post on this and some of the nuances/discrepancies for these S3 settings: <a href="https://www.cloudquery.io/blog/finding-enabled-s3-acls-and-disabled-s3-block-public-access" rel="nofollow">https://www.cloudquery.io/blog/finding-enabled-s3-acls-and-d...</a></p>
]]></description><pubDate>Mon, 30 Jan 2023 21:35:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=34586761</link><dc:creator>nutbear</dc:creator><comments>https://news.ycombinator.com/item?id=34586761</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34586761</guid></item><item><title><![CDATA[New comment by nutbear in "Nike.com allows easy account take over"]]></title><description><![CDATA[
<p>Thanks for sharing your story!<p>A decent amount of disclosure programs explicitly call out social engineering as unacceptable conduct and submissions.<p>However, social engineering is a very valid method for attackers and in many cases, offers the path of least resistance.<p>While I understand why companies don’t want good faith security research to call and try to trick the human factor, this is still a very real attack vector that needs attention and to be fixed as in what you’ve described.</p>
]]></description><pubDate>Tue, 19 Jul 2022 17:05:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=32154749</link><dc:creator>nutbear</dc:creator><comments>https://news.ycombinator.com/item?id=32154749</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32154749</guid></item><item><title><![CDATA[Uncontrollable AWS IAM: Sts:GetSessionToken, GetCallerIdentity, and Policy Sim]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.praetorian.com/blog/stsgetsessiontoken-role-chaining-in-aws/">https://www.praetorian.com/blog/stsgetsessiontoken-role-chaining-in-aws/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=31778442">https://news.ycombinator.com/item?id=31778442</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 17 Jun 2022 14:10:35 +0000</pubDate><link>https://www.praetorian.com/blog/stsgetsessiontoken-role-chaining-in-aws/</link><dc:creator>nutbear</dc:creator><comments>https://news.ycombinator.com/item?id=31778442</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31778442</guid></item><item><title><![CDATA[Shared VPCs in AWS]]></title><description><![CDATA[
<p>Article URL: <a href="https://aws.amazon.com/about-aws/whats-new/2018/12/amazon-virtual-private-clouds-can-now-be-shared-with-other-aws-accounts/">https://aws.amazon.com/about-aws/whats-new/2018/12/amazon-virtual-private-clouds-can-now-be-shared-with-other-aws-accounts/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=18606016">https://news.ycombinator.com/item?id=18606016</a></p>
<p>Points: 4</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 05 Dec 2018 06:04:33 +0000</pubDate><link>https://aws.amazon.com/about-aws/whats-new/2018/12/amazon-virtual-private-clouds-can-now-be-shared-with-other-aws-accounts/</link><dc:creator>nutbear</dc:creator><comments>https://news.ycombinator.com/item?id=18606016</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=18606016</guid></item></channel></rss>