Except it wasn’t “All Users in your AWS account”, it literally meant ALL USERS of AWS. Disaster. This led to the same problems as this Jira issue.
AWS changed it so that’s no longer an option. Atlassian should do the same.
Would we? Amazon requires you to explicitly make the bucket open. It also allows you to prevent that account-wide with IAM policies. It also allows delegating the opening to public to specific people.
And I believe you get warnings about public buckets from their advisor. (May be misremembering that one) You can easily audit that too.
So basically I don't see what else could AWS do to make this more secure. It's 100% on the user at this point.
By all current evidence, we'd blame Capital One, so I guess this is consistent?