0
Today while auditing a friends security settings, I found that an Amazon Folder (s3 bucket) with his most personal files had an unrecognised ACL entry.
A person (with id ending in f6995f) had "Write" access to the bucket. Weirdly no read or list access.
There's no name shown as username. Just an alphanumeric "canonical id" of the entity who has access.
What should he do? He can't contact AWS because
On the Basic Support Plan, you can create account and billing support cases and service limit increase requests, but you cannot create technical support cases.
Is there's a way to find out the person behind the canonical id? At least country/location/IP?
Relevant: https://docs.aws.amazon.com/general/latest/gr/acct-identifiers.html
– schroeder – 2019-03-22T17:08:57.577