Urgent.News

What's breaking now, across thousands of outlets.

Tech

I Ran a Security Scanner Against Mastodon, Discourse, and Chatwoot's AWS Defaults. Here's What I Found.

✓ Human-authored analysis; AI used for formatting and proofreading. You deploy a Rails app to AWS. You follow the README. File uploads work. You move on. But what just happened to the S3 bucket your app is writing to? Is it encrypted? Is it public? Could someone use it to ransom your data? I used Stave , an open-source configuration safety tool, to answer those questions for three of the most…

1. Three popular open-source Rails applications - Mastodon, Discourse, and Chatwoot - have been analyzed for security defaults in their AWS configurations. Stave, an open-source configuration safety tool, was used to scan the applications.

2. The scan revealed 47 security findings across the three projects. Two of the three default to publicly readable S3 buckets with no encryption, access logging, or Public Access Block enabled.

3. Mastodon defaults to public-read permissions for file uploads, making profile pictures, media attachments, and header images readable by anyone on the internet. Without S3 Public Access Block enabled, there is no account-level guard preventing this bucket or any bucket in the AWS account from being public.

4. Discourse, on the other hand, defaults to public-read ACLs through admin settings when secure uploads are disabled. This also results in files being readable by anyone on the internet.

5. Chatwoot, however, gets one thing right by defaulting to private objects with Active Storage when S3 is used. This prevents the default public-read issue seen in Mastodon and Discourse.

6. Despite its correct default, Chatwoot still has 15 security findings, the same as the other two applications, including critical findings around Server-Side Encryption (SSE-C) not disabled, lack of account-level Public Access Block, and the absence of encryption at rest.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

How we built a verified dataset of 198 tour group headset rules

Museums and historic city centres keep adding rules about how a tour guide may talk to a group. Some require headsets above a certain group size, some ban loudspeakers, and some do not let an outside…

  • Verified dataset of 198 tour group headset rules compiled
  • Rules categorized into three classes (A, B, C) with specific policies
  • Dataset open under CC BY 4.0 for public access on Hugging Face and Kaggle

Why Dev Teams Still Fight Over Semicolons

Every engineering team loses an afternoon to a religious war over code style. Tabs versus spaces. Trailing commas. Brace placement.

  • Teams argue over code style, causing productivity issues.
  • AI-generated code introduces stylistic inconsistencies.
  • Automated tools maintain consistency but can't solve deeper issues.

More from Friday 2 October →