TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

The last S3 Security document that you will ever need

6 pointsby brentcetinichover 3 years ago

1 comment

brentcetinichover 3 years ago
It is a 160 Page PDF on S3. If you are putting any confidential information in S3 you need to see the S3 service map in the PDF on page 3. All the different access points and places you can set an ACL... All the bolt on services that keep on piling on starts to show the age of the service.<p><a href="https:&#x2F;&#x2F;github.com&#x2F;trustoncloud&#x2F;threatmodel-for-aws-s3&#x2F;raw&#x2F;main&#x2F;Amazon%20Simple%20Storage%20Service%20(S3)%20-%20ThreatModel.pdf" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;trustoncloud&#x2F;threatmodel-for-aws-s3&#x2F;raw&#x2F;m...</a><p>Here is a nice threat:<p>Etags includes the MD5 of the file but not consistently and can be used by developers to verify the integrity of a file. An attacker can affect an upload function to change the etag of a file, in order to disrupt a workflow downstream.