There's a Hole in 1,951 Amazon S3 Buckets
community.rapid7.com
community.rapid7.com
The title and the first 80% of the article is written to allow a casual reader to infer that there is a problem with S3... simply put this isn't the case, and through brute force guessing the researchers were able to find some publicly accessible files containing sensitive information in a bucket... (assuming of course that the bucket owner didn't intend for the bucket to be public in the first place?)
This really isn't restricted or exclusive to just S3 buckets.. if you randomly hit enough web accessibly URLs you'll find confidential/sensitive material else where as well. People might feel slightly more confident or relaxed in what they store on S3, but the author doesn't make any convincing points to suggest this.
The findings are on a par with research such as "eating fatty food causes heart problems", or "exercise is good for you"... or "Amazon S3 service used as intended causes pages to be publicly accessible"...
If the Summly could do research TL;DRs as well, it would be, "S3 buckets set to public are accessible to anyone".
Removing public LIST access not only prevents charges from accruing from LIST operations but also allows you to keep your S3 resources semi-private even in a public bucket, by using hard-to-guess private URL's. Going to the root of the bucket no longer shows the list of files, instead it just shows an Access Denied message.
I don't know if Amazon still sends out the automated message, but if they do then those 1,951 open buckets are from people who either ignored the warning or couldn't figure out how to follow Amazon's instructions on how to fix the vulnerability.
So not really a hole so much as it's configured that way. Title implies that this is a breach of some kind, which it's not.
I appreciate that one can say they're carrying out important research, but did they notify the people with open buckets or are they more interested in PR?