Public usually means two things
An S3 bucket is public if anyone on the internet can
list or read objects — via a bucket ACL grant to
AllUsers / AuthenticatedUsers, or a bucket
policy with "Principal": "*" and an allow. AWS’s
Block Public Access (four flags, at the account
and/or bucket) is what stops that from happening by accident.
A bucket can also be “not public right now” but unprotected: Public Access Block is off, so the next IAM change or a copied ACL makes it public. That is the finding most scanners treat as medium; an actually-public bucket is critical.
Find it yourself
Account-level block (do this first if you do not host a public site from S3):
aws s3control get-public-access-block --account-id <12-digit>
Per bucket:
aws s3api list-buckets --query 'Buckets[].Name' --output text
aws s3api get-public-access-block --bucket <name>
aws s3api get-bucket-policy-status --bucket <name>
aws s3api get-bucket-acl --bucket <name>
PolicyStatus.IsPublic already accounts for Block Public
Access. ACL grants do not — if IgnorePublicAcls is on,
a leftover public ACL is inert. Turn all four flags on unless you
have a documented reason not to:
aws s3api put-public-access-block --bucket <name> \
--public-access-block-configuration \
BlockPublicAcls=true,IgnorePublicAcls=true,BlockPublicPolicy=true,RestrictPublicBuckets=true
Console: S3 → the bucket → Permissions → Block public access. Same four toggles exist at the account level (S3 → Block Public Access settings for this account). Account-level on is the cheapest insurance for every future bucket.
What is not this problem
- CloudFront in front of a private bucket with an origin access control — that can be fine.
- A static website you meant to publish. Then keep Block Public Access off only on that bucket, and lock the policy to
s3:GetObjecton the site prefix, nots3:*on*. - Objects that are public because someone set an object ACL years ago. Bucket-level Block Public Access with
IgnorePublicAclscovers that; object ACLs are otherwise easy to miss.
Where PostureRadar fits
PostureRadar lists every bucket, checks ACLs, policy status, and Block Public Access (bucket and account), and emails you. Public buckets come through as critical; missing Block Public Access without a current public grant is medium. It's $39 per account per month, weekly. The remediation guidance is the same four flags above.
Related: Stale IAM access keys · Why AWS Config gets expensive · Security Hub finding noise
