this post was submitted on 07 Apr 2024
514 points (95.7% liked)

Security

4939 readers
3 users here now

Confidentiality Integrity Availability

founded 4 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 159 points 5 months ago (4 children)

As much as I hate them, this is likey because a customer misconfigured their bucket and not on Amazon.

[–] [email protected] 24 points 5 months ago (1 children)

Yeah, I work for a Federal agency, and I can confirm this is an extremely plausible situation. Was probably a contractor.

[–] [email protected] 3 points 5 months ago

Good thing those are always necessary and efficient.

[–] [email protected] 18 points 5 months ago

I have never configure s3 buckets for an enterprise personally, but I have used AWS for some personal projects. The control panel pretty clearly warns you if you try to open the bucket to the public. "This is unsafe. Everyone can see everything you idiot!"

They must be doing it through the CLI.