Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

S3 buckets created/used should use a random suffix #566

Open
diego-ojeda-binbash opened this issue Apr 30, 2024 · 0 comments
Open

S3 buckets created/used should use a random suffix #566

diego-ojeda-binbash opened this issue Apr 30, 2024 · 0 comments

Comments

@diego-ojeda-binbash
Copy link
Contributor

Describe the Feature

According to this article, just knowing the name of a bucket, regardless of the bucket being private or public, issuing an unauthorized PUT request will charge the bucket owner.

At the moment, it seems that only making it difficult for attackers to know the bucket name is the only action we can take. That's why we suggest using a random suffix on the bucket name, which is one the recommendations the article makes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant