Hey folks, we've published a post with more details on the incident here: https://www.twilio.com/blog/incident-report-taskrouter-js-sd...
(I work for Twilio)
(I work for Twilio)
This incident report should really put to bed all of the "It's AWS's fault for making things so complex" complaints. (To be clear, it won't... but it should.)
Even a cursory look at that bucket policy should tell you something named "Allow Public Read" should NOT be associated with anything named 'Put'. This takes 0 AWS knowledge to figure out.
And stating to the press the clearly malicious payload is "non-malicious" (assuming TFA didn't lie about Twilio's statement)? That's ridiculous.
They owned it. That is more than can be said about other large incident reports that I've seen regarding AWS.