Skip to content
InfoQ·

🔒S3 Clones Fall Short on Security: Wiz Study Reveals Gaps

Your S3-compatible storage isn't as secure as you think

TL;DR

A new Wiz report exposes significant security flaws in popular S3-compatible services. Most lack AWS's robust protections, making them vulnerable to unauthorized access and data breaches.

Wiz researchers have uncovered major security gaps in six leading cloud providers' S3-compatible object storage services. The study reveals that these services fall short of Amazon S3’s comprehensive protection measures, leaving users exposed to risks like unauthorized access and data leaks. Developers using these services should be wary of public bucket handling, IAM capabilities, and secret-scanning support, which vary widely across providers. For instance, Crusoe and Lambda Labs lack public-access controls entirely, while others offer fewer protections than AWS S3's Block Public Access feature.

S3 Clones Fall Short on Security: Wiz Study Reveals Gaps — InfoQ

Key Points

1

Researchers examined six major cloud providers' S3-compatible object storage services for security flaws

2

AWS S3 has nearly 300 APIs compared to varying levels of functionality in clones, impacting IAM capabilities

3

Public bucket handling varies; Crusoe and Lambda Labs lack public-access controls entirely

4

Credentials are harder to detect on non-AWS platforms, complicating security audits and compliance checks

5

The study highlights multiple reported vulnerabilities, including one in MinIO enabling unauthorized privilege escalation

Why It Matters

If you're using S3-compatible services for object storage, your data's safety may be compromised. Public bucket handling varies widely, with some providers like Crusoe and Lambda Labs lacking critical public-access controls. This means that even if you follow best practices on AWS S3, moving to a clone could expose your buckets to unauthorized access.

S3-compatibleWiz ResearchSecurity GapsPublic BucketsIAM

Frequently Asked Questions

Why does this matter?

If you're using S3-compatible services for object storage, your data's safety may be compromised. Public bucket handling varies widely, with some providers like Crusoe and Lambda Labs lacking critical public-access controls. This means that even if you follow best practices on AWS S3, moving to a clone could expose your buckets to unauthorized access.

What happened?

A new Wiz report exposes significant security flaws in popular S3-compatible services. Most lack AWS's robust protections, making them vulnerable to unauthorized access and data breaches.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,281 builders reading daily.

Also get