Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why does this keep happening? It seems like every month there's a new leak from an open S3 bucket?


New companies with immature systems, old companies hiring young developers doing side stuff off in their own world, bad default configurations etc

Most importantly there's a large amount of highly incentivized people probing constantly at mass scale. These days it's very easy to scan the internet (github, IPs, domains, etc) for information and "bad S3 configuration" detection is just a script anyone can use. No advanced programming skills required.


S3 (and most of AWS) is terribly designed, so you end up googling for access policies that likely work when you are trying to get a new project off the ground. That policy may not be right for prod in the future.

Not saying it is right, it's just what happens.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: