you are viewing a single comment's thread
view the rest of the comments
[–] 4 points 2 years ago (2 children)

Bucket names are often committed to GitHub. It used to be that bucket names could be published but ever since the blog post of the guy getting fucked by people polling his bucket due to an open source project typo made others realize that bucket names should probably be secrets.

There are bots that will just monitor all public commits to github, gitlab, etc. for AWS credentials and other strings like that. And as soon as they are found they will start to abuse them.

  • source
  • parent
  • hideshow 2 child comments