news.volyx.in

AWS Support able to access any S3 object due to permission change (twitter.com)

450 points by zdw · 1731 days ago · 129 comments on HN

Article summary

AWS support personnel had temporary access to all S3 objects due to a permission change, which has since been reverted. This change did not affect KMS-encrypted objects, but may have impacted objects encrypted with S3-managed keys. The incident has raised concerns about data security and access controls on AWS. Users are advised to review their S3 bucket policies and encryption settings.

Main themes

  • AWS security incident
  • S3 object access
  • KMS encryption
  • cloud security risks
  • data protection
  • AWS responsibility and transparency

What commenters say

  • The incident highlights the importance of using client-side encryption or KMS-encrypted objects to protect data on AWS.
  • AWS support personnel should not have had access to customer data, even if it was temporary and reverted.
  • The cloud is not a secure way to store sensitive data, and users should consider alternative solutions.
  • Declaring a security incident is a necessary step to investigate and mitigate potential breaches, even if no actual breach occurred.
  • AWS has a responsibility to be transparent about data access and security incidents, and to provide clear explanations for changes to permissions and access controls.
  • The use of envelope encryption by AWS may compromise the security of data encrypted with S3-managed keys.
  • Users should be aware of the risks and limitations of storing data on the cloud, and take steps to protect their data accordingly.