3 ms·
Having witnessed what people do, it’s easy to prevent it now for the most part but badly written / enforced access controls and laziness (in the form of overcom
by devonkim 7y ago
Having witnessed what people do, it’s easy to prevent it now for the most part but badly written / enforced access controls and laziness (in the form of overcommit of engineers to projects) are the norm for most large companies. Most of the compromised buckets were launched years ago before a lot of safeguards were put in, and object level permissions can override bucket policies anyway. Getting sharing of objects across a Byzantine bureaucracy in internal IT is a great way to increase the chance some engineer desperate to get their work done will mark something public and forget about it.
S3 based URLs to get cheap web hosting for low traffic sites is exactly what leads to bad permissions as well. I’ve seen plenty of S3 objects that are made public so that they can be viewed from a web browser and are just a badly targeted script run away from being on the latest tech blog about how some other institution leaked PII.