AWS IAM Security

The cluster focuses on discussions about AWS IAM's security features, best practices like using roles and short-lived credentials instead of root keys, potential vulnerabilities, and debates on its complexity and effectiveness.

📉 Falling 0.3x Security
3,692
Comments
19
Years Active
5
Top Authors
#5704
Topic ID

Activity Over Time

2008
2
2009
9
2010
15
2011
20
2012
49
2013
56
2014
132
2015
142
2016
171
2017
229
2018
160
2019
274
2020
388
2021
479
2022
523
2023
389
2024
376
2025
257
2026
21

Keywords

UserGuide S3 AWS SSH ACL alias.html CRD IAM SSM docs.aws aws credentials instances s3 ec2 account secret access role keys

Sample Comments

Temporary_31337 • Feb 27, 2024 • View on HN

I feel like the potential to abuse this is pretty low but AWS will ‚fix’ this and make IAM even harder

EGreg • Jul 28, 2016 • View on HN

Do you realize that your AWS account can be compromised without something like this?

toomuchtodo • Jun 30, 2021 • View on HN

AWS IAM is no different.https://news.ycombinator.com/item?id=24498678

toomuchtodo • Oct 19, 2015 • View on HN

Enable two factor auth on your AWS account. Chances of fraud quickly approach zero unless your AWS API creds are leaked. You should always be using an IAM account that has only the privileges your application requires.

lexalizer • Dec 31, 2014 • View on HN

This happens very often. Like many others have recommended, disable the global AWS keys and use roles.

paulgb • Feb 27, 2025 • View on HN

Only if you give it unfettered accesss. AWS has an API called AssumeRole which can generate short-lived credentials with a specifically scoped set of permissions, which I use instead.

the_arun • Oct 24, 2017 • View on HN

Isn't this a huge security hole in AWS?

benwilson-512 • Jan 26, 2020 • View on HN

This looks very cool. Is there a story for managing users associated with AWS IAM roles or users?

dijonman2 • Jul 9, 2022 • View on HN

It’s a security disaster, you have to give developers aws admin in order to use it. At least that’s how it used to be. I stood it up in a separate account for this reason.

sofixa • Mar 30, 2021 • View on HN

Uhm.. in the AWS i've used, it's on explicit allow, and all of their docs and tutorials start with IAM and what's needed and why. What more do you want? I can't imagine IAM being simpler while being as granular as it is. You just have to actually take the time to learn about it, like every system. It's still drastically easier to use it securely than doing something on a similar scale and detail manually.