4 ms·
This is all really obvious though... The title and the first 80% of the article is written to allow a casual reader to infer that there is a problem with S3...
by richardv 14y ago
This is all really obvious though...
The title and the first 80% of the article is written to allow a casual reader to infer that there is a problem with S3... simply put this isn't the case, and through brute force guessing the researchers were able to find some publicly accessible files containing sensitive information in a bucket... (assuming of course that the bucket owner didn't intend for the bucket to be public in the first place?)
This really isn't restricted or exclusive to just S3 buckets.. if you randomly hit enough web accessibly URLs you'll find confidential/sensitive material else where as well. People might feel slightly more confident or relaxed in what they store on S3, but the author doesn't make any convincing points to suggest this.
The findings are on a par with research such as "eating fatty food causes heart problems", or "exercise is good for you"... or "Amazon S3 service used as intended causes pages to be publicly accessible"...
If the Summly could do research TL;DRs as well, it would be, "S3 buckets set to public are accessible to anyone".
- malandrew 14y agoTrue. However, there is value in a company like Amazon licensing or creating their own suite of tests like those performed by this researcher that would warn users if they are likely exposing files publicly that they probably shouldn't be exposing. e.g. "We found that the following files appear to contain password data and are publicly viewable. Are you sure you want these files to be listed publicly?
- res0nat0r 14y agoAWS actually already does proactively monitor and send out alert emails to customers who have LIST enabled to Everyone on their S3 buckets, which is a good thing.
- pekk 14y agoAnyone who has learned to use S3 knows that there is a usability problem with S3.
- papsosouid 14y agoPermissions on S3 are not at all easy or intuitive, and the documentation on it is terrible. Even setting up very simple scenarios is a huge hassle, and it doesn't surprise me at all that there's tons of buckets with incorrect permissions as a result.