I use S3 and I have noticed that by default it's locked down and secure and in order for it to be open you have to open it for the public. Maybe AWS could improve the way it can secure the S3 buckets by making it easier to whitelist access by IPs or some variant to this. Although I personally find it fairly straight forward to use in the projects I work on but it appears it may be difficult and my developers just open it up to the public so their apps can easily access it.