My Lemmy Oracle
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
lengau@midwest.social to Programming@programming.devEnglish · 1 year ago

How an empty S3 bucket can make your AWS bill explode

medium.com

external-link
message-square
16
fedilink
  • cross-posted to:
  • [email protected]
81
external-link

How an empty S3 bucket can make your AWS bill explode

medium.com

lengau@midwest.social to Programming@programming.devEnglish · 1 year ago
message-square
16
fedilink
  • cross-posted to:
  • [email protected]
Imagine you create an empty, private AWS S3 bucket in a region of your preference. What will your AWS bill be the next morning?
alert-triangle
You must log in or register to comment.
  • deegeese@sopuli.xyz
    link
    fedilink
    arrow-up
    41
    ·
    1 year ago

    “By design” AWS bills project owners for unauthorized calls to the public S3 API.

    So what I’m reading from this is you can do a billing attack on anything hosted in AWS so long as you know one of their bucket names.

    • bamboo@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      5
      ·
      1 year ago

      Seriously, now that this is more widely known, it’ll for sure be taken advantage of a lot, to the point AWS will begrudgingly protect their customers once the damage is done.

  • wpuckering@lm.williampuckering.com
    link
    fedilink
    arrow-up
    35
    ·
    edit-2
    1 year ago

    You shouldn’t be charged for unauthorized requests to your buckets. Currently if you know any person’s bucket name, which is easily discoverable if you know what you’re doing, that means you can maliciously rack up their bill just to hurt them financially by spamming it with anonymous requests.

    • NegativeLookBehind@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      1 year ago

      This is insane.

      • gravitas_deficiency@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        lol dude, I’ve known several people who have worked at AWS for years, and the amount of duct tape and bailing wire Mickey Mouse shit that I’ve heard goes on there just… does not inspire confidence.

  • AmbiguousProps@lemmy.today
    link
    fedilink
    English
    arrow-up
    22
    ·
    1 year ago

    As it turns out, one of the popular open-source tools had a default configuration to store their backups in S3. And, as a placeholder for a bucket name, they used… the same name that I used for my bucket.

    • LostXOR@fedia.io
      link
      fedilink
      arrow-up
      3
      ·
      1 year ago

      deleted by creator

  • Deebster@programming.dev
    link
    fedilink
    arrow-up
    10
    ·
    1 year ago

    A great post, interesting and to the point.

  • neo (he/him)@lemmy.comfysnug.space
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    1
    ·
    1 year ago

    Please use scribe.rip instead of medium.com for articles

    https://nomedium.dev/

    • atzanteol@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      6
      ·
      1 year ago

      It’s fine if you dislike a site. But the correct thing to do is not consume their content, not to work around it.

      • borari@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        1
        ·
        1 year ago

        Medium is the journalistic version of the gig economy apps, mixed with a bit of digital landlording. The correct thing to do here is to bypass any of Mediums paywalls you might run in to.

  • sensiblepuffin@lemmy.world
    link
    fedilink
    arrow-up
    6
    ·
    1 year ago

    AWS was kind enough to cancel my S3 bill. However, they emphasized that this was done as an exception.

    Dicks.

  • Hupf@feddit.de
    link
    fedilink
    arrow-up
    1
    ·
    1 year ago

    I has a bucket

    • Chronographs@lemmy.zip
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      That’s a rare vintage

  • Cosmic Cleric@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    6
    ·
    1 year ago

    Wow, makes one fearful to even use AWS. Yikes!

    Definately required reading for those who use AWS.

    CC BY-NC-SA 4.0

Programming@programming.dev

programming@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!

Cross posting is strongly encouraged in the instance. If you feel your post or another person’s post makes sense in another community cross post into it.

Hope you enjoy the instance!

Rules

Rules

  • Follow the programming.dev instance rules
  • Keep content related to programming in some way
  • If you’re posting long videos try to add in some form of tldr for those who don’t want to watch videos

Wormhole

Follow the wormhole through a path of communities [email protected]



Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 74 users / day
  • 583 users / week
  • 2.6K users / month
  • 7.95K users / 6 months
  • 1 local subscriber
  • 22.7K subscribers
  • 2.41K Posts
  • 34.6K Comments
  • Modlog
  • mods:
  • snowe@programming.dev
  • Ategon@programming.dev
  • MaungaHikoi@lemmy.nz
  • UlrikHD@programming.dev
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org