Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Source blog post (and free of CNN's obnoxious autoplay video): https://www.upguard.com/breaches/cloud-leak-chicago-voters

As soon as I read the headline, I immediately thought "AWS misconfiguration". A few recent massive government-data breaches (by contractors) have fallen into that category:

June 2017: http://gizmodo.com/gop-data-firm-accidentally-leaks-personal...

May 2017: http://gizmodo.com/top-defense-contractor-left-sensitive-pen...

Note that all of these breach reports (including this Chicago one) come from Upguard, which seems to have a method for scanning/crawling public S3 buckets.



Amazon just launched a service to help scan, categorize, and protect data https://aws.amazon.com/macie/


This looks like it only works for buckets you own. Upguard is scanning everyone.


Don't you have to pay for that?


One click away: https://aws.amazon.com/macie/pricing/

"No charge for the first 1 GB processed by the content classification engine After first GB, $5 per GB processed by the content classification engine"


Wow that seems pricey. $5 just to look over a Gig of data with a fancy algorithm?

...data that's already on their servers, to boot!


Thanks! We've updated the link from http://money.cnn.com/2017/08/17/technology/business/chicago-..., which points to this.


Same with Nice Systems' leak of Verizon customers' data:

https://www.engadget.com/2017/07/12/verizon-partner-exposes-...


I made a quick-and-dirty tool for doing this: https://github.com/sa7mon/S3Scanner

I'll probably spend some time this weekend making things look better and improving the documentation. I made it mostly as a PoC




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: