3 ms·
Does that mean people still have tons of public-by-mistake s3 buckets because of their clumsy UI, and they just gave up and are swiping what's left under the r
by gcb0 7y ago
Does that mean people still have tons of public-by-mistake s3 buckets because of their clumsy UI, and they just gave up and are swiping what's left under the rug?
- ceejayoz 7y agoThis wouldn't have any impact on that issue. Those accidentally-public buckets are already accessible in both the path-based and the virtualhost-based method.
- scarface74 7y agoYou really have to try to make a bucket public. Even when you do, you get warnings within the UI, and there is a column showing you it’s public. Is there even a UI option to make a bucket public anymore? I always edit the bucket policy and add the JSON to make it public read only.
- ceejayoz 7y agoA lot of that is a fairly recent development, though. Lots of buckets laying around from the years it largely didn’t warn you.
- marcinzm 7y agoThey're not public by "mistake". They're public because someone was lazy, wanted to share something and didn't want to bother with authentication. They knew they were making it public but figured no one would find it except the desired recipient so why put in the effort to make a better solution.