Access is easy to grant
and nobody's job
to take back.
That is the whole story.
Someone needed the database
for one afternoon
in a bad week
two years ago.
They still have it.
They don't know they have it.
You don't know they have it.
The key outlived
the reason.
A contractor left in spring.
The laptop went back.
The badge went back.
The token in the pipeline settings
stayed,
quietly,
with permission to deploy.
An integration you tried once
and never adopted
still holds a scope
that reads every file you own.
None of this looks like an attack.
It looks like housekeeping
nobody scheduled.
Nobody hands a stranger
the keys to production.
We just never take back
the keys we handed
to people we trusted
in a different year.
But an intruder
does not need to break a door
that paperwork
left open.
So book the boring hour.
List every human,
every service account,
every token,
every third-party app
you clicked allow on
while trying to get something done.
Then ask one question of each:
if this vanished tonight,
who would notice by morning?
If the answer is nobody,
it should not exist.
Delete it.
Not next quarter. Now.
Start with the accounts
that belong to nobody.
The ones named after
a project that shipped,
a vendor you left,
a script somebody wrote
for one migration
in a month you can barely recall.
You will break something.
Good.
A thing breaking loudly
in daylight
with everyone watching
is the cheapest
security incident
you will ever have.
Cheaper than the same thing
found by a stranger
at three in the morning
with time to look around.
Then fix the source.
Give access an expiry
the moment you grant it,
so the default is closed
and someone has to argue
to keep it open.
Permissions are not a gift.
They are a loan
you forgot to call in.
The safest credential
is the one
that no longer exists.
– Serguey Asael Shinder
Top comments (0)