API Security

  • Amazon gives us a lot of cool APIs to interact with their platform
  • The API can...
    • Create and manage servers
    • Create and manage users
    • Store data in a "bucket"
    • and almost anything else you can do in the console
  • Not all resources should have access to all these abilities
  • These actions can't be easily controlled in the network

