DinkMeeker's comments

DinkMeeker | 5 years ago | on: Good Heavens 10M Impacted in Pray.com Data Exposure

> “Through further investigation, we learned that Pray.com had protected some files, setting them as private on the buckets to limit access,” they explained. “However, at the same time, Pray.com had integrated its S3 buckets with another AWS service, the AWS CloudFront content delivery network (CDN). Cloudfront allows app developers to cache content on proxy servers hosted by AWS around the world – and closer to an app’s users – rather than load those files from the app’s servers. As a result, any files on the S3 buckets could be indirectly viewed and accessed through the CDN, regardless of their individual security settings.”

I have minimal knowledge of this kind of configuration, but it seems like making content available via a CDN from the same vendor should by default carry forward access restrictions on the original backend data.

page 1