3 ms·
I agree AWS can do a lot better with the tooling UX, but adding write permissions like this is a conscious decision. In this case, someone purposefully added it
by somethingwitty1 6y ago
I agree AWS can do a lot better with the tooling UX, but adding write permissions like this is a conscious decision. In this case, someone purposefully added it (outside the creation UX flow). I'm not sure we can put the blame squarely on AWS for this one.
And they definitely haven't been doing nothing. They've drastically redesigned the permissions UX around S3 over the years. They introduced GuardDuty to allow automatic threat detection (such as S3 bucket having open permissions) which can be applied across your organization (not just an account). They definitely have to keep doing more, but implying they are doing nothing just isn't true.