Live data from Hacker News

AWS Support able to access any S3 object due to permission change

twitter.com

131–134 of 134 posts

Re: AWS Support able to access any S3 object due to permission change

#131
post #55

Earlier quoted context omitted.

this should be the default user behaviour for any cloud storage. Don't put unencrypted (company) data on a cloud infrastructure you don't have full control over. Also reminds me of the (hyped?) "outrage" when a former facebook developer stated that they used to have a "default password" that allowed fb devs to log into every account and the media were like "omg they could have logged in and seen your photos". I mean.…

What does "full control in the cloud" mean to you? It sounds like that's an oxymoron in your opinion, but correct me if I'm wrong. I get the idea, but also realize this is fundamentally incompatible with using the range of services at AWS. Fringe-future tech aside, you need unencrypted data to process it and use it. AWS isn't just S3, it's lambda, it's hosting and data science and databases. Having just read the twee…

With full control I mean things like having access logs for everything that goes in and out the box (like when you selfhost a minio instance)

Re: AWS Support able to access any S3 object due to permission change

#132

Earlier quoted context omitted.

They started the Schwarz Group Cloud (Stackit), 8000 developers and yet not a single production ready service yet.

where do you got that 8000 developer number from? Sounds like a lot

https://www.discountretailconsulting.com/post/germany-schwar...

Re: AWS Support able to access any S3 object due to permission change

#133

Earlier quoted context omitted.

The first premise when using a vendor is trust. If you don't trust them then don't use them. So far, AWS has proven to be trustworthy in my opinion. From what little I've seen about their operations they seem to give a damn and you have to assume that iceberg goes deep. If you don't trust them, don't use them. Provide evidence to your leadership of malicious intent and provide an alternative and they'll back you. Exe…

This seems very binary / black-and-white to me - it’s not “you either trust them or don’t”. I may trust AWS to keep the cloud running, but I may not want to trust all their stuff with access to my private data. If a provider puts themselves in a position that they’re entirely unable to access my data, or it being extremely difficult, that would actually increase my trust in them. If having all customer’s private S3 d…

I don’t trust any data hosting. Any company can be forced to monitor it or allow government a copy.

If your data leaves your network and it’s supposed to be private, encrypt it in such a way only the people who should be able to read it can read it.

Re: AWS Support able to access any S3 object due to permission change

#134

Earlier quoted context omitted.

where do you got that 8000 developer number from? Sounds like a lot

https://www.discountretailconsulting.com/post/germany-schwar...

You have misread, it talks about the open source platform OpenStack, and that over 8000 thousand developers work on OpenStack.
Post reply on HN