Hacker News new | past | comments | ask | show | jobs | submit login

It's pretty easy to restrict which users can access IMDS, if you want to do that.



The problem is that the default is wide open.


I'm not sure what can really be done about that while still allowing custom AMIs with arbitrary operating systems. "Talk to local network" is a pretty generic interface.


AMIs are already specialized for virtualization. To get full performance, guests need a whole pile of specialized drivers. Most are industry standards, but they’re still specialized for VM. Adding one more for IDMS v3 and similar mechanisms from other providers seems straightforward to me.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: