Hacker News new | past | comments | ask | show | jobs | submit login

> a former AWS engineer who abused her access

Nowhere in the criminal complaint[1] does it say this happened. Instead it says that Paige wrote a script that scanned web application firewalls (WAFs) for a specific vulnerability. Anyone could have done this. The problem was only possible because after abusing the vulnerability Paige discovered that the IAM Role used by the WAF was granted permissions it shouldn't have.

1. https://www.justice.gov/usao-wdwa/press-release/file/1188626...




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: