this post was submitted on 07 Apr 2024
530 points (95.8% liked)

Security

5041 readers
1 users here now

Confidentiality Integrity Availability

founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] reverendsteveii@lemm.ee 61 points 7 months ago (8 children)

I work in a HIPAA-covered industry and if our AWS and GCP buckets are insecure that's on us. Fuck Amazon, but a hammer isn't responsible for someone throwing it through a window and a cloud storage bucket isn't responsible for the owner putting secret shit in it and then enabling public access.

[–] zalgotext@sh.itjust.works 19 points 7 months ago (3 children)

Yeah I hate Amazon as much as the next person, but this is a people/process problem, not an Amazon problem. Amazon doesn't know or care what you put into an AWS bucket (within reason, data tracking, etc, blah blah blah). People taking classified documents and uploading it to an Internet-connected cloud service is procedurally wrong on so many levels.

load more comments (1 replies)
load more comments (5 replies)