|
|
|
|
|
by wkat4242
175 days ago
|
|
An 'open S3 bucket' sounds really bad. If it were posted on an HTTPS site without authentication, like the firmware for most devices, it wouldn't sound so bad. Sure an open bucket is bad, if it's stuff you weren't planning on sharing with the whole world anyway. |
|
But how is an open, read-only S3 bucket worse than a read-only HTTPS site hosting exactly the same data?
The only thing I can see is that it is much easier to make it writeable by accident (for HTTPS web site or API, you need quite some implementation effort).