3 ms·
What used to be behind firewalls oftentimes became accidentally public through the many, many blunders of publicly available S3 buckets that people started to u
by devonkim 7y ago
What used to be behind firewalls oftentimes became accidentally public through the many, many blunders of publicly available S3 buckets that people started to use because they were frustrated with AWS IAM. This is ironic because IAM was supposed to help you secure your data and such, not make things worse for your security profile. Even with all the tooling that exists to help people write better IAM policies and figure things out, cross-account IAM permissions and roles, S3 bucket policies, etc. are a nightmare for most people beyond fairly seasoned engineers in AWS and that's a problem. Secure-by-default is not quite 100% true with most AWS services in practice unfortunately.
- ecnahc515 7y agoIt's extremely easy to prevent publically available S3 buckets, and there's even built in policies for it. It's actually fairly difficult to make a bucket public without going through a few hoops even without that. The only reason this is happening is sure laziness and lack of any true change control processes. It's not because it's hard.
- devonkim 7y agoHaving witnessed what people do, it’s easy to prevent it now for the most part but badly written / enforced access controls and laziness (in the form of overcommit of engineers to projects) are the norm for most large companies. Most of the compromised buckets were launched years ago before a lot of safeguards were put in, and object level permissions can override bucket policies anyway. Getting sharing of objects across a Byzantine bureaucracy in internal IT is a great way to increase the chance some engineer desperate to get their work done will mark something public and forget about it. S3 based URLs to get cheap web hosting for low traffic sites is exactly what leads to bad permissions as well. I’ve seen plenty of S3 objects that are made public so that they can be viewed from a web browser and are just a badly targeted script run away from being on the latest tech blog about how some other institution leaked PII.