Thanks for sharing. After digging in, it appears that something very similar happened here, after all. It looks like an access key with admin role leaked some time ago. At first, they just ran a quiet GetCallerIdentity, then sat on it. Then, on outage day, they leveraged it. In our case, they just did the SES thing, and tried to persist access by setting up IAM Identity Center.
These were accounts that shouldn't have had console access in the first place, and were never used by humans to log in AFAICT. I don't know exactly what they were originally for, but they were named like "foo-robots", were very old.
At first I thought maybe some previous dev had set passwords for troubleshooting, saved those passwords in a password manager, and then got owned all these years later. But that's really, really, unlikely. And the timing is so curious.
I would normally say that "That must be a coincidence", but I had a client account compromise as well. And it was very strange:
Client was a small org, and two very old IAM accounts had suddenly had recent (yesterday) console log ins and password changes.
I'm investigating the extent of the compromise, but so far it seems all they did was open a ticket to turn on SES production access and increase the daily email limit to 50k.
These were basically dormant IAM users from more than 5 years ago, and it's certainly odd timing that they'd suddenly pop on this particular day.
I find your public road network analogy interesting. Should your car require you to prove your age before it will start? How else can we protect your kid (and others) from the dangers of an 8 year old taking the family sedan for a spin?
I think there's diminishing returns. A broad, liberal arts, undergraduate education develops critical thinking and reading skills in a zero-to-one kind of way. Once you've attained those skills (whether through a college degree or some other way), further enrichment via self-study is much more easily doable.
I don't get your strong objection. A 1.0 release that is fit for use by >80% of the addressable market, and gets high marks from those users is a "boondoggle"?
Perhaps you overestimate the fraction of taxpayers that itemize deductions, have gig/rental/business income?
Structuring (splitting up cash deposits to a bank so that they don't trigger the bank to file a CTR) comes to mind. It does have a mens rea component, but the money being entirely clean doesn't make the act not-structuring, IIUC.
Monopoly concerns are better addressed by going after monopolies for being anticompetitive. Intermediary liability seems pretty orthogonal to competition concerns. I would need a lot of convincing to start believing that categories like search or even social media (despite network effects) are natural monopolies akin to railroads or POTS-type phone companies of yore – where you can't have efficient competition, and don't have thorny 1A issues to deal with, so common-carrier approaches are defensible.
As an aside, one reason I think 230 pretty much correct is that authoritarians on both sides of the spectrum want to axe it, but for different reasons.
That thinking strikes me as "clear, simple, and wrong". (I appreciate that 230's bright-line rule may also be clear, simple and wrong)
Consider defamation. Often, the difference between a defamatory and non-defamatory statement is truth. Expecting websites to distinguish true statements from false ones is a non-starter.
Let's say my family has a horrible experience with a youth pastor. I post about it on facebook to warn people in my community. If my claims are false, they're almost certainly actionable defamation. If my claims are true, disallowing them to mitigate Facebook's potential liability is also bad, but not in a way that affects Facebook.
The idea that there's an indistinct difference between "publisher" and "common carrier" doesn't seem right. Google or Facebook are not, and have never been, common carriers. The entities that most resemble "common carriers", as that term is historically used, are infrastructure-layer companies. I don't see how the distinction could be sharper.
The "idea that these providers are simply neutral carriers of content" is a false premise, isn't it?
The piece you link is ... weird. First, it doesn't really describe the problem it's trying to solve. Then it presents some very vague policy prescriptions like "site[s] should be regulated by sector-specific rules that apply to that particular line of business".
Is this person a lawful agent of a legitimate government? Is the ice cream policy reasonably connected to some compelling government interest, like public health?