4 ms·
I agree that S3 is fantastic, but not sure I would consider it simple considering how much sensitive data is left wide open in publicly accessible buckets all t
by mtberatwork 7y ago
I agree that S3 is fantastic, but not sure I would consider it simple considering how much sensitive data is left wide open in publicly accessible buckets all the time. Clearly, applying correct permissions seems to be quite a challenge for even experienced folks. The S3 console doesn't really make life any easier either and terminology can be confusing. Also, applying IAM/CORS policies, object headers, etc isn't exactly simple for the layperson.
- deleted 7y ago[deleted]
- scarface74 7y agoYou have to jump through hoops to make buckets public and even then you get a clear label saying “public”.
- alpha_squared 7y agoThe "public" label was somewhat recent (I think that happened in the last 18 months), but I think many of the biggest S3 leaks predate that labeling.
- madeofpalk 7y agoThe S3 console now makes it quite apparent, in my opinion when things are left public. Public is no longer the default, and theres big scary warnings whenever you make something public.
- deleted 7y ago[deleted]
- saber6 7y ago> I agree that S3 is fantastic, but not sure I would consider it simple considering how much sensitive data is left wide open in publicly accessible buckets all the time. You're conflating two things: A) simple, reliable service B) dumbass operators. Yes, I said it: If you leave a public bucket exposed in S3 unintentionally, you're a dumbass. You're also most likely not appropriately skilled (security fundamentals) for the responsibilities you have been charged with (information security). Neither of these are the fault of AWS or S3. S3 is a tool, like a pick axe. If you ram it through your foot, it is not the pick axe's fault.
- alpha_squared 7y agoBuckets are private by default and always have been. A bucket needs to be made public. Given that, I would hazard a guess that buckets are often made public (when they shouldn't be) for either testing purposes and never reverted or because creating proper access to the bucket took too much time/knowledge.
- ratww 7y agoThat's most certainly the reason. I sometimes have to support freelancers working in some of our Wordpress websites. Their first instinct when something is wrong on their end is asking me to run a chmod or chown command they found on Google on the whole directory. Not that it matters – we're using Docker. Security seems to be secondary when the priority is to just deliver.
- salamander014 7y ago> Security seems to be secondary when the priority is to just deliver. Security is always an afterthought to those who don't actually understand it.
- klodolph 7y agoSecurity should be secondary. I know that sounds wrong. And that’s not an absolute, sometimes security comes first. But in general, everyone is trying to get stuff done and security gets in the way. My passwords get in the way of using my devices. My keys gets in the way of coming home. That’s different from saying “security should be an afterthought”. Security is something you should consider consciously and prioritize against your other goals. Putting security first is kind of weird if you think about it. Imagine building a house and prioritizing the locks.
- xref 7y agoSeveral billion people don’t have easy, immediate access to your house locks.
- elithrar 7y ago
- ceejayoz 7y agoA shotgun is pretty simple. It'll still blow your head off.