this post was submitted on 07 Apr 2024
483 points (95.3% liked)

Security

4980 readers
3 users here now

Confidentiality Integrity Availability

founded 4 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] cloud_herder 38 points 6 months ago

To be fair, it’s probably more about the IT contractors and consulting firms that didn’t implement security policies or configurations correctly on the S3 buckets for the governments they’re working for. The AWS products aren’t opening up things to the public internet without auth. Which I bet most of you knew.

Example: Accenture left a trove of highly sensitive data on public servers (2017)