S3 Compatibility Doesn't Guarantee S3-Level Security
Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.
Security gaps in S3-compatible storage is technically deep, actionable for cloud architects, and strategically important.
Security researchers at Wiz audited six neocloud S3-compatible services (Nebius, Crusoe, Vultr, Lambda Labs, Cloudflare R2, DigitalOcean) and found critical gaps versus AWS S3, including missing Block Public Access controls, non-standard access key formats that evade GitHub secret scanning, and inconsistent IAM semantics. One tested service deleted the entire bucket on a `delete-bucket-policy` call, highlighting that API compatibility does not imply security parity. The report warns that teams relying on S3 clones cannot assume AWS-level least-privilege protections and must explicitly audit each provider's behavior.