AWS IAM Security

The cluster focuses on discussions about AWS IAM's security features, best practices like using roles and short-lived credentials instead of root keys, potential vulnerabilities, and debates on its complexity and effectiveness.

📉 Falling 0.3x Security
3,692
Comments
19
Years Active
5
Top Authors
#5704
Topic ID

Activity Over Time

2008
2
2009
9
2010
15
2011
20
2012
49
2013
56
2014
132
2015
142
2016
171
2017
229
2018
160
2019
274
2020
388
2021
479
2022
523
2023
389
2024
376
2025
257
2026
21

Keywords

UserGuide S3 AWS SSH ACL alias.html CRD IAM SSM docs.aws aws credentials instances s3 ec2 account secret access role keys

Sample Comments

Temporary_31337 Feb 27, 2024 View on HN

I feel like the potential to abuse this is pretty low but AWS will ‚fix’ this and make IAM even harder

EGreg Jul 28, 2016 View on HN

Do you realize that your AWS account can be compromised without something like this?

toomuchtodo Jun 30, 2021 View on HN

AWS IAM is no different.https://news.ycombinator.com/item?id=24498678

toomuchtodo Oct 19, 2015 View on HN

Enable two factor auth on your AWS account. Chances of fraud quickly approach zero unless your AWS API creds are leaked. You should always be using an IAM account that has only the privileges your application requires.

lexalizer Dec 31, 2014 View on HN

This happens very often. Like many others have recommended, disable the global AWS keys and use roles.

paulgb Feb 27, 2025 View on HN

Only if you give it unfettered accesss. AWS has an API called AssumeRole which can generate short-lived credentials with a specifically scoped set of permissions, which I use instead.

the_arun Oct 24, 2017 View on HN

Isn't this a huge security hole in AWS?

benwilson-512 Jan 26, 2020 View on HN

This looks very cool. Is there a story for managing users associated with AWS IAM roles or users?

dijonman2 Jul 9, 2022 View on HN

It’s a security disaster, you have to give developers aws admin in order to use it. At least that’s how it used to be. I stood it up in a separate account for this reason.

sofixa Mar 30, 2021 View on HN

Uhm.. in the AWS i've used, it's on explicit allow, and all of their docs and tutorials start with IAM and what's needed and why. What more do you want? I can't imagine IAM being simpler while being as granular as it is. You just have to actually take the time to learn about it, like every system. It's still drastically easier to use it securely than doing something on a similar scale and detail manually.