Comment by progbits
3 days ago
Couldn't agree more.
Yet many of these tools have setup like: create a service account, give it about thousand permissions (if not outright full ownership) and send us the JSON private key.
At least they make the red flag nice and obvious.
No comments yet
Contribute on Hacker News ↗