logoalt Hacker News

SkyPunchertoday at 5:33 PM1 replyview on HN

These tools are useful, but I can't help to feel like they're solving the wrong part of the problem. I really don't have much concern that an agent has access to one of my credentials. Outside of production, most of these credentials are going to be limited in privilege and self-rotatable.

What remains terrifying is the ability to exfil important data or run commands that are malicious.


Replies

jadengellertoday at 5:35 PM

exfiltrating a credential provides persistent access (until detected and rotated) tho! probably one of the more leveraged things to prevent