I'm storing files (UUID + extension) on a bucket, data is not confidential but should not be public is it a big security/privacy issue is I set the bucket policy to public?
CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.
@mur2501 this is mainly a private application, URL with link to S3 would not be publicly available
the only thing that goes to me is an enumeration bruteforce if the bucket URL leaks
the policy I used:
{ "Version": "2012-10-17", "Statement": [ { "Sid": "PublicRead", "Effect": "Allow", "Principal": "*", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::BUCKET/*" } ] }