My sympathy for companies that decide to employ such tools is very limited.
nunez•9mo ago
It's always an unsecured S3 bucket. S3 buckets these days have deny ACLs by default, so it must have been an _aged_ bucket.
TheNewsIsHere•9mo ago
I could also see this being a bucket that was explicitly configured to be open. Perhaps because that’s what it was in dev/test for ease of work, and the CodeFormation/Terraform/CLI script/whatever deployed the bucket to prod, was just cargo-culted right from dev/test with no review. Happens a lot these days.
nunez•9mo ago
That's just bad practice. It is very easy to run tests against secured S3 buckets. But, yeah, unfortunate that this is common.
Hizonner•9mo ago
Well, there's a shock. Play stupid games, win stupid prizes.
kQq9oHeAz6wLLS•9mo ago