duo-labs / duo-labs/cloudmapper

Identify vendors that are not publicly documented

Open
#816 1 comment 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
JavaScript
Stars
6.3k
Forks
836
PR merge metrics
No merged PRs in 30d

Description

We've had some PRs to add vendor accounts that aren't publicly documented. I've generally avoided these because:
1) The vendor might not want their account ID to be publicly known (not a great reason since there aren't any known threats for someone knowing your account ID)
2) What if an account is added that is wrong? Maybe an attacker tells me their account belongs to some vendor. Then I add it here and now a security team ignores some backdoor in their account?

However, I want this repo to have a complete list of known vendor accounts, and not have people have to maintain their own private lists or some other awkward solution.

As such, I think it makes sense to add in these vendors, but to indicate that I'm not entirely confident this info is true. This resolves reason 2 of not including them, and these vendors are just going to have to live with me ignoring reason 1.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.