After string of breaches, Amazon upgrades security features for cloud server

A new warning feature will appear on multiple spots across the console, while a privacy feature includes support to encrypt all S3 data by default.
By Jessica Davis
10:03 AM
AWS cloud server

After a long line of customers failed to properly secure their data and exposed massive amounts of data to the public, Amazon Web Services has decided to update its S3 server dashboard with a visible warning for server admins that data are publically accessible.

The new warning feature is a bright-orange button that appears in various spots across the AWS console. The company said the idea is for admins to see these warnings and review access rights of the S3 buckets to avoid exposing sensitive data to the public.

Prior to the new features, admins would need to create a bucket policy that would reject unencrypted objects to ensure all objects were encrypted. The new tool lets the user install a bucket encryption configuration to make sure objects are encrypted using the specified method.

[Also: Data on 150,000 patients exposed in another misconfigured AWS bucket]

Essentially, the new feature would include support for encrypting all S3 data by default.

Further, the new dashboard clearly labels buckets that are publicly accessible and lets admin control the privacy settings of each block with an access control list.

The database will also send daily and weekly inventory reports that include the encryption status of each object -- and the report can also be encrypted.

[Also: Kromtech launches tool to identify and prevent Amazon cloud server leaks]

All of the new security options are provided at no extra cost to customers.

The AWS dashboard updates come after a year with a long line of massive breaches, stemming from admins failing to properly configure databases.

Just last month, Accenture breached client data in four separate buckets after its admin accidentally left the data open to the public. Third-party vendor Patient Home Monitoring exposed the data of more than 150,000 patients after it failed to lock its data down.

Verizon is also part of the group, as it recently notified 14 million of its customers that their personal data was left exposed online. Other high profile companies and health systems have also accidentally breached data in this manner by failing to secure data in the cloud.

Twitter: @JessieFDavis
Email the writer:

Want to get more stories like this one? Get daily news updates from Healthcare IT News.
Your subscription has been saved.
Something went wrong. Please try again.