> Just a thought, but you don’t store them in an unprotected S3 bucket.
> If you’re required to handle this kind of sensitive information ... you should take every precaution that that information is secure, encrypted when possible, and that your systems are regularly audited for vulnerabilities.
None of that solves the problem, though.
You can protect an S3 bucket, but anyone who wants it simply checks it periodically.
Then one day someone is working with the data and changes the permissions to get access, and before they know it, it's downloaded in minutes. It just takes one attacker to get lucky and catch it before your audits do.
And S3 is not unusual, it's just an Internet service like any other, they all have this problem. Even if you have your own data center on a private network, it's only private until someone needs to transmit something and opens a route.
It's ultimately a human problem, there's no magic that can prevent it.
> If the onus ... you shouldn’t be in that type of business. Period.
Ending an unjustified opinion with "period" highlights the fact that you didn't justify the opinion. And it sounds fatuous.