4 ms·
With the amount of information leaks that have occurred from S3 buckets being public, I'm surprised this wasn't fixed a decade ago.
by skunkworker 4y ago
With the amount of information leaks that have occurred from S3 buckets being public, I'm surprised this wasn't fixed a decade ago.
- _cenw 4y agoBoth were made default at their inception, at least on the console. You need to remember the S3 API is from 2006 and Amazon probably measure how many buckets are created with these 17 year old defaults and then actually stay and rely on these defaults.
- orev 4y agoPublic access by default was a boneheaded decision from the very beginning. Even in 2006 it was already well-known for decades how public anonymous access to things could lead to problems. All they needed to do was provide a checkbox to enable public access.
- nickvanw 4y agoI've never worked at AWS, but I have worked on smaller systems where people depended on defaults. Speaking first hand, it is EXTREMELY difficult to get changes to defaults shipped on a system with as much usage as S3. You are, inevitably, going to break someone's workflow for a reason that you cannot possibly fathom. They are going to be unhappy. At least one of them is going to come across your boss' boss' desk and they're going to wonder if this change is _really_ necessary. Every incentive, even with this default behavior being bad, is to leave it the way it is. Respect to the AWS people that got this across the line.