Charged for empty buckets
One for Cloudy people. I didn’t know that a failed and unauthorised (PUT) request to your private AWS S3 bucket, from anyone or anywhere, would be charged to you by AWS.
Sure it’s a fraction of a cent for 1000 requests. But if someone knew the name of your bucket(s), held a grudge, and could write a script…
Hopefully they’re all named something not very obvious, not published, and you don’t just allow anyone to create one without controls.
An interesting security story about open source software using S3 as backup as well in that read. Somebody also thinks Azure has similar
Hmm, shared responsibility model eh?