| ▲ | staticassertion 2 hours ago | |||||||||||||||||||||||||
> At the end of the day with all data that is colocated you're trusting that some permission feature somewhere is preventing you from accessing data you're not supposed to. Right but ideally more than one. > But it's all just mostly logical separation. Yes, ideally multiple layers of this. You don't all share one RDS instance and then get row level security. | ||||||||||||||||||||||||||
| ▲ | Philip-J-Fry 2 hours ago | parent [-] | |||||||||||||||||||||||||
Can you give an example of more than one layer of logical separation at the data layer? We all know that authentication should have multiple factors. But that's a different problem. Fundamentally at the point you're reading or writing data you're asking the question "does X has permission to read/write Y". I don't see what you're getting at. | ||||||||||||||||||||||||||
| ||||||||||||||||||||||||||