5 ms·
The new S3 console/flow sets to private by default - so some progress there, all jokes aside.
by STRML 9y ago
The new S3 console/flow sets to private by default - so some progress there, all jokes aside.
- nhumrich 9y agoS3 has always been private by default. But too many people open it up to the world for convenience.
- mtgx 9y agoYes, but now Amazon will show them orange alerts if they do that! I've argued this before around here - I believe it's a platform provider's responsibility for the most part to secure data, and less so the responsibility of the developer or user. Amazon should go much further and make it hard to open-up the data to the public, at least for certain categories of buckets. So for instance some buckets should always be public by default, and some should always be encrypted and private by default. That should make intelligence agencies' choice easier, because I would imagine even if it's "harder" to process the data from an encrypted bucket, they would still prefer that option to the always public bucket. And maybe both categories could still be configured to either be private or public, respectively, but the account owners should have to really go out of their way to make those changes. So most shouldn't bother, and just use the defaults for each category of buckets.
- colechristensen 9y ago>I believe it's a platform provider's responsibility for the most part to secure data, and less so the responsibility of the developer or user I would say that is going too far, or maybe I'd say it differently. If a certain problem becomes very frequent relative to it's severity, the problem is a design bug and not just user error. The provider isn't responsible for every mistake, but they are responsible for designing with mistakes in mind.
- staticassertion 9y agoIf your design allows insecure setups without users understanding the risks in full, I think that's on the providers and not the user. If the user understands the risks fully, then it's on the user. I think we are way far away from users fully understanding the risks, and we're still mostly dealing with people not realizing they're vulnerable. So I put this primarily on the provider.
- mtgx 9y agoAnd it only took the Pentagon exposing its main surveillance operation to get Amazon to make that change. Progress. I wonder what other improvements we'll see when CIA's surveillance or drone strike data is also exposed to the public by a similar fuckup? Fully homomorphic encryption?