Urgent.News

What's breaking now, across thousands of outlets.

Tech

An empty result is not an all clear

An infrastructure audit runs across your account and comes back with two findings on S3. You fix both, close the ticket, and move on. What the report did not tell you is that the role running it lacks s3:GetEncryptionConfiguration . Fourteen buckets returned AccessDenied on that call. The tool caught the rejection, wrote encrypted: false , and moved on to the next bucket. Some of those fourteen…

A recent infrastructure audit revealed that an S3 audit tool missed detecting some buckets as unencrypted, leading to a false sense of security. The tool, which ran across the account, found two issues on S3, but it lacked the necessary permissions to retrieve encryption configurations for 14 buckets. The tool incorrectly assigned encrypted: false to all buckets, including those that were actually encrypted.

This issue, which affected multiple infrastructure scanners, stemmed from a bug in how the tool handled rejected API calls.

When an API call failed, the tool treated it as if the bucket did not exist or had no encryption configuration, even when the call was rejected due to insufficient permissions. This resulted in the tool generating false findings, which appeared identical to real issues and were treated as such by downstream systems. The true unencrypted buckets remained undetected, creating a false negative that could mislead engineers and security teams.

To resolve this issue, the boolean field used to represent encryption status needed to be expanded to include a third state, null, to indicate that the encryption status could not be determined. This change ensured that the analyzer could distinguish between an observation (versioning turned on) and an error (failed to read the bucket configuration). By properly identifying and handling these rejections, the tool could accurately report unencrypted buckets, preventing false negatives and false positives.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Thursday 13 August →