Stave flagged 47 security findings in the documented AWS defaults of Mastodon, Discourse and Chatwoot, according to a dev.to post. None of the three configures bucket encryption, access logging or Public Access Block, so whoever creates the bucket has to add them.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+25
- Incentives
- Insufficient
- Confidence55
Four HackerOne reports cited in a dev.to analysis trace to S3 write scope set wider than the one object an upload needs. Only one of them is the starts-with key condition that turns a signed upload form into write access across a whole prefix.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives35
- Confidence55
In HackerOne 121461 a researcher created the missing bucket in their own AWS account and served files on a2.bime.io. The state that allowed it is a name sitting in the DNS zone with no matching bucket in the account.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+30
- Incentives85
- Confidence60
In HackerOne report #3022516 the trail was multi-region, the metric filter for unauthorised API calls existed and the alarm published to an SNS topic, while threat_detection.enabled read false. Turning it on costs one CLI call.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives65
- Confidence60
A pool created with the defaults treats a password as the whole authentication factor and scores no risk on the sign-in. In the HackerOne chain a dev.to writeup walks through, either setting turned on would have stopped the takeover.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives68
- Confidence52
A policy that lets users read and manage their own IAM profile usually carries iam:AttachUserPolicy scoped to ${aws:username}. That scope is enough to attach AdministratorAccess to yourself in a single call.
Reality
- Evidence66
- Adoption
- Insufficient
- Hype gap+20
- Incentives70
- Confidence56
A dev.to write-up prints the ClusterRole that gives an operator four write verbs on mutating webhook configurations, then the two manifest lines that make the resulting persistence read as a healthy cluster.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+26
- Incentives70
- Confidence55
A CloudGoat walkthrough moves an API key through SNS into API Gateway and back out of Lambda. Access Analyzer and PMapper both report the user has no access.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+34
- Incentives72
- Confidence46
A dev.to post ships a deliberately misconfigured AWS environment and a CSV scorecard so tools can be graded on found-versus-missed. The comparison it argues for has not been published yet.
Reality
- Evidence30
- Adoption8
- Hype gap+22
- Incentives72
- Confidence42
All eleven issues score within half a point, so the ranking is useless for triage. One practitioner's decomposition puts 93 of 112 checkable properties inside a config snapshot, and 19 outside it.
Reality
- Evidence32
- Adoption
- Insufficient
- Hype gap+34
- Incentives86
- Confidence33