logoalt Hacker News

epistasisyesterday at 10:28 PM1 replyview on HN

Aws credentials are short lived precisely so that leaking them has a time limited blast radius.

Automatic retrieval, instead of keeping them on disk, is what makes short lived credentials possible.


Replies

Sohcahtoa82yesterday at 11:54 PM

I'm not convinced that time-limiting the blast radius matters. It just means that malicious use of the credentials has to be automated, and that's a pretty damn low bar.