Live data from Hacker News

AWS Support able to access any S3 object due to permission change

twitter.com

31–40 of 134 posts

Re: AWS Support able to access any S3 object due to permission change

#31
post #22

I have been looking into this lately for a company that wanted to host important data on AWS S3. I couldn’t find conclusive information in public domain. It’s hard to decipher the AWS Data Privacy policy: https://aws.amazon.com/compliance/data-privacy-faq/ In section Who Owns Customer Content, it’s implied that AWS doesn’t access customers’ data: “As a customer, you maintain ownership of your content, and you select…

> AWS doesn’t access customers’ data Amazon's product people also don't look at third party seller statistics to decide which products to sell themselves. Until they got caught doing just that. To assume that they don't look at data feels naive. A German super market chain with online ambitions has a rule that nothing touching their pipeline can be hosted on AWS. Want to sell them SaaS? You can't run your nodes on AW…

> A German super market chain

Which one? I would like to support non-AWS-companies.

Re: AWS Support able to access any S3 object due to permission change

#32
post #31

Earlier quoted context omitted.

> AWS doesn’t access customers’ data Amazon's product people also don't look at third party seller statistics to decide which products to sell themselves. Until they got caught doing just that. To assume that they don't look at data feels naive. A German super market chain with online ambitions has a rule that nothing touching their pipeline can be hosted on AWS. Want to sell them SaaS? You can't run your nodes on AW…

> A German super market chain Which one? I would like to support non-AWS-companies.

Lidl

Re: AWS Support able to access any S3 object due to permission change

#33

When I worked in aws, this is primarily used to check for permissions of an object. I know how dumb customers can be, for the most part this is used to see why a customer cannot delete a bucket or object those sort of things. I don't remember having ability to see actual customers data only metadata is accessible. Edit: Based on what I know, I'm pretty sure support will not be able see any of the customers data.

> I know how dumb customers can be I find this insulting as a customer. Is AWS usually contemptuous of its customers? I don't think I've ever called my customer "dumb", and working as a consultant I've seen all kinds of interesting things. People make mistakes. They're always in a hurry. They may have a hard time understanding ambiguous, complex or incomplete documentation. The interface may be confusing and lead the…

As a customer, I don’t take it as an insult, we all can (as per gp) be dumb on occasion, without actually being dumb in general. On the other hand, the comment did not offer much assurance with regards to the topic at hand either.

Re: AWS Support able to access any S3 object due to permission change

#34

Earlier quoted context omitted.

> AWS doesn’t access customers’ data Amazon's product people also don't look at third party seller statistics to decide which products to sell themselves. Until they got caught doing just that. To assume that they don't look at data feels naive. A German super market chain with online ambitions has a rule that nothing touching their pipeline can be hosted on AWS. Want to sell them SaaS? You can't run your nodes on AW…

They started the Schwarz Group Cloud (Stackit), 8000 developers and yet not a single production ready service yet.

So, is this fake? https://www.stackit.de/en/cloud/products-services/

Re: AWS Support able to access any S3 object due to permission change

#35

Earlier quoted context omitted.

They started the Schwarz Group Cloud (Stackit), 8000 developers and yet not a single production ready service yet.

So, is this fake? https://www.stackit.de/en/cloud/products-services/

no, definitly not. but Lidl don‘t run a single production service on it yet.

Re: AWS Support able to access any S3 object due to permission change

#36

When I worked in aws, this is primarily used to check for permissions of an object. I know how dumb customers can be, for the most part this is used to see why a customer cannot delete a bucket or object those sort of things. I don't remember having ability to see actual customers data only metadata is accessible. Edit: Based on what I know, I'm pretty sure support will not be able see any of the customers data.

> I know how dumb customers can be (...)

This sort of personal attack is unwarranted and extremely unfair. AWS is renowned for it's byzantine and ever-changing and expanding nature, to the point it's outright practically impossible to know extremely basic things such as what are you paying for and how much you are paying.

Re: AWS Support able to access any S3 object due to permission change

#37
post #22

I have been looking into this lately for a company that wanted to host important data on AWS S3. I couldn’t find conclusive information in public domain. It’s hard to decipher the AWS Data Privacy policy: https://aws.amazon.com/compliance/data-privacy-faq/ In section Who Owns Customer Content, it’s implied that AWS doesn’t access customers’ data: “As a customer, you maintain ownership of your content, and you select…

> AWS doesn’t access customers’ data Amazon's product people also don't look at third party seller statistics to decide which products to sell themselves. Until they got caught doing just that. To assume that they don't look at data feels naive. A German super market chain with online ambitions has a rule that nothing touching their pipeline can be hosted on AWS. Want to sell them SaaS? You can't run your nodes on AW…

AFAIK Walmart has that rule too.

Re: AWS Support able to access any S3 object due to permission change

#38

Earlier quoted context omitted.

So, is this fake? https://www.stackit.de/en/cloud/products-services/

no, definitly not. but Lidl don‘t run a single production service on it yet.

I guess you have inside information but my naive assumption, reading the website doc and guessing how this things work, is that Scwarz group created it on top of their already existing self-service infrastructure, they "just" opened to external customers. Or did they create it from scratch?

Re: AWS Support able to access any S3 object due to permission change

#39
I'm not sure what the hoo hah is about.

All that's changed is that this role is now visible in IAMS and any API calls by Amazon support tools will be logged in AWS CloudTrail - I don't think AWS have any more access now than they did before.

It's obvious to anyone who has had problems with any AWS services (lambda functions that couldn't be deleted, non properly propagating/operational services) that support has access to them via their tools.

https://docs.aws.amazon.com/awssupport/latest/user/using-ser...

Re: AWS Support able to access any S3 object due to permission change

#40

Earlier quoted context omitted.

> AWS doesn’t access customers’ data Amazon's product people also don't look at third party seller statistics to decide which products to sell themselves. Until they got caught doing just that. To assume that they don't look at data feels naive. A German super market chain with online ambitions has a rule that nothing touching their pipeline can be hosted on AWS. Want to sell them SaaS? You can't run your nodes on AW…

They started the Schwarz Group Cloud (Stackit), 8000 developers and yet not a single production ready service yet.

where do you got that 8000 developer number from? Sounds like a lot
Post reply on HN