Reading view

What is the dumbest AWS security mistake you've actually found in the wild?

Not the theoretical stuff from a security checklist.

I mean the kind of thing where you look at an AWS account and think:

I'm building an open-source AWS security scanner and I've started realizing that the interesting part isn't just how many checks a scanner has.

It's whether those checks actually catch the weird stuff people accidentally leave behind.

For example, one of the first real accounts someone tested my scanner against had a forgotten access key that nobody realized was still there.

That got me thinking:

What are the security mistakes that AWS developers actually make repeatedly, but security tools don't make obvious enough?

Could be:

  • forgotten IAM users/keys
  • overly permissive security groups
  • weird cross-account trust policies
  • unused privileges
  • public resources
  • logging gaps
  • something completely different

I'm collecting real examples because I want to turn them into better test cases for Plexavo.

What's the most ridiculous AWS security/configuration mistake you've personally encountered?

Bonus points if it's something a scanner would normally miss.

submitted by /u/kavee-core141 to r/devops
[link] [comments]
  •  

Should I stay in DevOps/SPE path or change career to Data Analytics?

I'm deciding whether to continue down the cloud engineering/DevOps/SRE path or change to business or data analytics. I’ve been working in IT for about six years, starting in help desk and systems administration and eventually moving into cloud migrations. I also have certifications in Azure, GCP, CCNA, and CompTIA, so most of my experience has been centered around infrastructure and cloud technologies. One friend thinks I should stay on this path because I’ve already invested so much time into it and could continue progressing toward cloud engineering, DevOps, or eventually SRE. The concern I have is interviews for SRE roles ask about almost anything including multiple cloud platforms, Terraform, Kubernetes, scripting languages, monitoring tools like Grafana and Prometheus, CI/CD, networking and feel like SAT tests.

Another friend suggested that I consider business or data analytics instead. His argument is that analytics may be less stressful, potentially offer a better work-life balance without on-call responsibilities, and that I might ultimately be happier in that type of role. He also thinks the interviews may be less intense and require a narrower range of knowledge compared with DevOps/SRE. I’ve used SQL and Power BI briefly in previous positions, so I’m not completely starting from zero, although I haven’t held a full-time analytics position. I realize I might have to take a pay cut initially, but I’m wondering whether that could be worthwhile if it leads to a career I enjoy more?

For those who have worked in cloud/DevOps/SRE and/or business/data analytics, how would you compare the stress, interview difficulty, learning curve, career growth, and work-life balance? Would you recommend building on my existing cloud background, or change careers into analytics? Which would make more sense at this point in my career?

submitted by /u/Unique-Ferret-612 to r/devops
[link] [comments]
  •  
❌