Taffer, to AWS
@Taffer@mastodon.gamedev.place avatar

I briefly looked at AWS S3 Glacier storage, thinking maybe having a second cloud host for my backups would be good.

I can't actually figure out how much this will cost me because they charge per operation (you know, like PUT, GET, etc.) in addition to the storage costs (which I easily figured out).

The kicker? I work at AWS. 🤷

timbray, to fediverse
@timbray@cosocial.ca avatar

In which I notice that AWS’s S3 is getting more and more competition all the time, and thus the object-storage space is becoming interesting, and also that there’s a angle: https://www.tbray.org/ongoing/When/202x/2024/05/05/On-Storage
Names are named.

kerfuffle, to AWS
@kerfuffle@mastodon.online avatar

People may want to reconsider using for static web hosting, or at the bare minimum come up with convoluted names and treat their S3 bucket name as sensitive information. If your S3 bucket name comes up in any web search (for example because it's literally in a public GitHub repo), that's a potential attack vector.

https://medium.com/@maciej.pocwierz/how-an-empty-s3-bucket-can-make-your-aws-bill-explode-934a383cb8b1

frankel, to AWS
@frankel@mastodon.top avatar
encthenet, to Amazon
@encthenet@flyovercountry.social avatar

The whole S3 charging for unauthorized/denied accesses to shows exactly the culture of . Just because they reversed this policy (TBD if they actually do) doesn't mean that other similar policies will be changed. That the support person couldn't raise concerns, that the middle managers didn't care enough about the customers to realize how bad/stupid/damaging it is.

steve, to AWS
@steve@mastohack.com avatar

I haven’t tested this myself, but it seems this may be a very nasty way to inflict targeted or random harm against anyone with #AWS #S3 buckets.
#infosec

https://medium.com/@maciej.pocwierz/how-an-empty-s3-bucket-can-make-your-aws-bill-explode-934a383cb8b1

publicvoit, to Amazon German
@publicvoit@graz.social avatar

hat den den Vorfall von https://medium.com/@maciej.pocwierz/how-an-empty-s3-bucket-can-make-your-aws-bill-explode-934a383cb8b1 in eigenen Worten gefeatured: https://blog.fefe.de/?ts=98ce33e2

Wahnsinn. Die ist ja wirklich ein tolles Ding ... um Amazon Geld zu besorgen. 🤣

Wirklich unglaublich, was man da liest. Da werden viele Firmen teures Lehrgeld zahlen, bis sie wegen Kostenexplosion vielleicht doch wieder in eigenes Wissen und Know-How investieren, sofern noch möglich ...

phphil, to AWS
@phphil@phpc.social avatar

Absolutely wild. You pay AWS for unauthorized requests (4XXs) to S3.

I can make a request to your bucket, and you will be charged.

via https://medium.com/@maciej.pocwierz/how-an-empty-s3-bucket-can-make-your-aws-bill-explode-934a383cb8b1

michael, to AWS
@michael@thms.uk avatar

What on earth?! Amazon S3 charges you for unauthorised requests to S3?!

That's just absolutely insane! I better check my AWS account and delete any unused buckets I have in there …

https://medium.com/@maciej.pocwierz/how-an-empty-s3-bucket-can-make-your-aws-bill-explode-934a383cb8b1

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • Youngstown
  • mdbf
  • everett
  • slotface
  • khanakhh
  • ethstaker
  • rosin
  • kavyap
  • GTA5RPClips
  • tacticalgear
  • JUstTest
  • DreamBathrooms
  • ngwrru68w68
  • Durango
  • normalnudes
  • cubers
  • modclub
  • cisconetworking
  • tester
  • osvaldo12
  • provamag3
  • anitta
  • Leos
  • lostlight
  • All magazines