How might this matter? A obvious one: Given a production bucket, it’s now possible to find development buckets for that same org, which is not expected behavior IMO.
Only true if they use the same accounts for both production and development. This would be another reason not to use the same accounts.
You only need the bucket name to do that. You should include a randomly generated prefix/suffix in bucket names to prevent against such enumeration attempts. Another good idea (as well as, not instead of) is to expose objects in buckets publicly with a non-default host name, such that the bucket name isn’t leaked at all.
Or, for read scenarios, putting a CloudFront distribution in front of the bucket!
How so?
You'd have the know the name of the (development) bucket first, right?
And this is why you pad the bucket name with random chars.
And Cloudformation will do this as the default
Unlikely, unless dev buckets are somehow in the same account.
it's bad practice but it's more common than you think especially with older accounts (pre-organization)