AWS error exposed GoDaddy business secrets
zdnet.com
zdnet.com
"The bucket in question was created by an AWS salesperson
to store prospective AWS pricing scenarios while working
with a customer," an AWS spokesperson told Engadget.
It's bad when even AWS employees misconfigure security on buckets... That feels like about three layers too low.
Pretty much my entire feeling on AWS's UX every time I want to do something simple5-10 years ago, I'd have said credential stuffing in your accidentally-exposed admin app.
Today, without question: it's AWS misconfiguration or credential leaking.
By AWS themselves? Does that actually happen a lot?
I'm not sure if that's meant to be sarcastic or serious.
I also question how bad it really would have been if the entirety of the information was leaked to the public. This is more embarrassing for AWS than GoDaddy.
Hidden right at the end Godaddy even downplays the sensitivity of the information that was available.
Except that GoDaddy has a massive, massive brand with millions invested in marketing over years of business. Its success is hardly down to trade secrets or juicy AWS discounts...
Title makes it seem like AWS system flaw, it's not.
Possible lessons: Why is it so easy/tempting/overlookable to misconfigure a bucket that an AWS employee could do it? What lessons can we learn from, for instance, Google Apps, where you don't usually misconfigure your file share? Upguard's conclusions are what you should be taking away, not "AWS buckets are fine from a tech standpoint".
Sales people turn on Public so clients can see it w/o logging into some system.
IMO an employee intentionally set a bucket with critical data to public.
My original point that the title was misleading stands.
The World Wide Web as a system allowed this deliberately public configuration, so the web is at fault.
AWS S3 as a system allowed this deliberately public configuration. So AWS S3 is at fault.
None of those seem quite right.
To me, seems more like AWS S3 isn’t designed for the higher level use case of sending a “shared secret” folder link by email to a collaborator, combined with a drinking the kool-aid tic where all employees try solving all use cases with the in-house hammer at hand.
At the same time, I think AWS has made a mistake — putting a Web Console on top of an API driven infrastructure, and investing so much recently in trying to make the web UI more “usable”.
AWS is not your father’s webmin VPS, but by now the console is so friendly, today’s sales guy can be forgiven for thinking S3 config and Dropbox config are the same thing.