Hacker News new | past | comments | ask | show | jobs | submit login

He said

> But such a feature could also be used to create a fake 169.254.169.254 (AWS/Cloud metadata IP address endpoint) and serve requests from it.

Wouldn’t such a thing be impossible if the application is using end-to-end encrypted requests to AWS?




the metadata service is http and not encrypted.




Consider applying for YC's W25 batch! Applications are open till Nov 12.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: