duo-labs / duo-labs/cloudmapper
Identify vendors that are not publicly documented
- Dominant language
- JavaScript
- Stars
- 6.3k
- Forks
- 836
- PR merge metrics
- No merged PRs in 30d
Description
We've had some PRs to add vendor accounts that aren't publicly documented. I've generally avoided these because:
1) The vendor might not want their account ID to be publicly known (not a great reason since there aren't any known threats for someone knowing your account ID)
2) What if an account is added that is wrong? Maybe an attacker tells me their account belongs to some vendor. Then I add it here and now a security team ignores some backdoor in their account?
However, I want this repo to have a complete list of known vendor accounts, and not have people have to maintain their own private lists or some other awkward solution.
As such, I think it makes sense to add in these vendors, but to indicate that I'm not entirely confident this info is true. This resolves reason 2 of not including them, and these vendors are just going to have to live with me ignoring reason 1.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.