{
  "id": 11439090,
  "title": "I Ran a Security Scanner Against Mastodon, Discourse, and Chatwoot's AWS Defaults. Here's What I Found.",
  "url": "https://urgent.news/2026/10/02/i-ran-a-security-scanner-against-mastodon-discourse-and-chatwoots-aws",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-02T12:38:32.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/bala_paranj_059d338e44e7e/i-ran-a-security-scanner-against-mastodon-discourse-and-chatwoots-aws-defaults-heres-what-i-32pe"
  },
  "original_language": "en",
  "account": "1. Three popular open-source Rails applications - Mastodon, Discourse, and Chatwoot - have been analyzed for security defaults in their AWS configurations. Stave, an open-source configuration safety tool, was used to scan the applications.\n\n2. The scan revealed 47 security findings across the three projects. Two of the three default to publicly readable S3 buckets with no encryption, access logging, or Public Access Block enabled.\n\n3. Mastodon defaults to public-read permissions for file uploads, making profile pictures, media attachments, and header images readable by anyone on the internet. Without S3 Public Access Block enabled, there is no account-level guard preventing this bucket or any bucket in the AWS account from being public.\n\n4. Discourse, on the other hand, defaults to public-read ACLs through admin settings when secure uploads are disabled. This also results in files being readable by anyone on the internet.\n\n5. Chatwoot, however, gets one thing right by defaulting to private objects with Active Storage when S3 is used. This prevents the default public-read issue seen in Mastodon and Discourse.\n\n6. Despite its correct default, Chatwoot still has 15 security findings, the same as the other two applications, including critical findings around Server-Side Encryption (SSE-C) not disabled, lack of account-level Public Access Block, and the absence of encryption at rest.",
  "summary": "✓ Human-authored analysis; AI used for formatting and proofreading. You deploy a Rails app to AWS. You follow the README. File uploads work. You move on. But what just happened to the S3 bucket your app is writing to? Is it encrypted? Is it public? Could someone use it to ransom your data? I used Stave , an open-source configuration safety tool, to answer those questions for three of the most…",
  "key_points": [
    "Three open-source Rails apps analyzed for AWS security defaults",
    "47 security findings across Mastodon, Discourse, Chatwoot",
    "Mastodon defaults to public-read S3 buckets with no encryption"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}