> Except one of the biggest initial selling points is hosting static websites, which requires the bucket to be public.
Maybe S3 should just be separated into buckets and websites. They can work the same under the hood, but call them something different to prevent this issue. Right now a lot of the new (and existing) security settings don't make any sense in the context of websites, and having the functionality to make websites within S3 creates security issues for everyone else.
Maybe S3 should just be separated into buckets and websites. They can work the same under the hood, but call them something different to prevent this issue. Right now a lot of the new (and existing) security settings don't make any sense in the context of websites, and having the functionality to make websites within S3 creates security issues for everyone else.