Can you point to a time Amazon did something like that? Not saying they won't, just any company can do it, it's more likely when they've done it in the past.
HN user
whoisthisfor
Adding to this wish list, the ability to rotate a token automatically. I'd like to do something like this with secrets manager, but GitHub's API just doesn't allow it - https://docs.aws.amazon.com/secretsmanager/latest/userguide/...
AWS Cryptography is hiring SDEs, Managers, Security Engineers, and Technical Program Managers.
https://docs.aws.amazon.com/encryption-sdk/latest/developer-...
Full Disclosure: My team built this but could be helpful. Doesn't do SRP, just encrypts data.
Everytime I dig into PAKEs, I find disappointment. If we all used a PAKE from the start of computers, maybe we'd be better off, but that's just because we would have been burned by them a dozen times. Right now the tech is very immature and asking a Dev to use these is essentially asking them to pick a cipher mode and padding for AES. There are no browser native SRP implementations and WebCrytpo doesn't support the primitives. The complexity these add isn't worth it for your vanilla website, IMO.
I'd be fine with either AWS or Azure getting the contact. It makes sense to pick one provider, as their workloads are ... unique.
Can we stop with PGP please? It has served its purpose.
Who ever owns .wedding owns the business vertical for weddings? This just doesn't add up. There might be good reasons to split Amazon up, but this isn't one of them.
https://slack.engineering/engineering-dive-into-slack-enterp...
This shows the KMS key is in the customer's AWS account.
You read my mind. I'd love if it could be rooted in a Yubikey.
Decoupling the "signing" and "verifying" parts seem like a good idea. As random Person signs something, how someone else figures out how to go trust that signature is a separate problem.
Is there anything out there that doesn't need GPG? Having a working GPG install is a huge lift for developers.
I disagree with:
can’t easily jump to another the way they can at Google or Apple.
I've never worked at Google or Apple, but I work in AWS. I see people switching teams, across different organizations within AWS and the retail business. When I first started, you had to stay on your team for 1 year before you could transfer, now there is no such restriction.
I will agree with the
encouraging teams to operate independently using whatever technology makes the most sense