User: you charge me when people make unauthorised requests to an S3 bucket?

AWS: yes of course

User: but

AWS: working as intended

User: but

AWS: thank you for your money

medium.com/@maciej.pocwierz/ho

@jonty The bucket names are not really secret, as you can make URLs up using them as part of the domain. This is a huge monetary risk for all AWS customers using S3 and doesn't give much credence to the "Shared Responsibility Model" that AWS use whenever they are blamed for security issues.

Follow

@merospit @jonty

Does this apply for billing too? The bucket is also simply a part of the query url.

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.