Score:0

Are files in a public GCS bucket discoverable?

cn flag

I have a bucket in GCS that I have made publicly available. Are objects stored in this bucket publicly discoverable?

For example, if the bucket is called my-public-bucket and I have an object in that bucket called 38bdac44efec6c54136fbfab496d0a16.key is there any way someone can figure out that object name (short of guessing, of course)? Is the list of all the objects in that bucket publicly available?

cn flag
I'm fairly certain unsecured *anything* ends up on Shodan. Accenture established that seven years ago. I've received alarms about our data showing up on data blob sharing web sites that was placed there by our vendors only minutes earlier... there are companies that specialize in looking for idiots doing this and offering its discovery as a service... sounds like you could use it. https://www.securityweek.com/misconfigured-public-cloud-databases-attacked-within-hours-deployment/
Sathi Aiswarya avatar
in flag
yes you can only list the objects, you cannot or remove objects let me know if that helped you, if not acknowledge it so we can solve it further
I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.