TIL wildcards on IAM principals are way more dangerous than I though (means literally any principal on any account not just yours). #DevSecCon