While we are on the topic of stupid:

Default security settings for S3 buckets usually allow only authorised users to access the contents; however, UpGuard reports the bucket was configured via permission settings to allow any AWS “Authenticated Users” to download its stored data.

What’s that mean you ask?

Authenticated users are any user that has an AWS account.


Posted by Ben Brooks