Reply to post: Re: Honest question

Video-editing upstart bares users' raunchy flicks to world+dog via leaky AWS bucket

GruntyMcPugh Silver badge

Re: Honest question

We still have am AWS bucket from a 'Cloud' project that failed to deliver. It was secure when we got it, and I have a tool 'CloudBerry Explorer' which allows me to check the permissions etc. The really odd thing I find about this though, is that when I authenticate to AWS, I don't get delivered directly to our bucket, but a couple of levels above, so I have to drill down. But that means I can see lots of other buckets, and I always found that odd, I know obscurity is no security, but being able to see the the bucket makes it easier to exploit from the outset.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon