Wildcard permissions widen blast radius
A permission that says "everything in this category" grants things nobody has thought about, including things that do not exist yet.
It gets used because enumerating the actual list is tedious and something breaks when you miss one. The cost is that the account now holds capabilities nobody intended, and will automatically gain more when the provider adds new ones. It is the difference between an account that can do nine things and an account that can do whatever becomes possible later.
More on Authorisation and privilege
- Least privilege decays over timeNobody hands the old one back
- Break-glass access should be exceptional and noisyLoud on purpose
- Privilege boundaries matter more than job titlesRead the account, not the business card
- Permission inheritance can hide excessive accessGranted upstairs, arrives downstairs
- Deny rules can create hard guardrailsOne no ends it
- Admin tools are part of the privileged access pathThe hand is not on the system
