{"slug": "s3-compatibility-doesn-t-guarantee-s3-level-security", "title": "S3 Compatibility Doesn't Guarantee S3-Level Security", "summary": "Security researchers at Wiz found that S3-compatible object storage services from Nebius, Crusoe, Vultr, Lambda Labs, Cloudflare R2, and DigitalOcean lack many of Amazon S3's security protections, including Block Public Access and structured access-key formats, creating a false sense of portability. The report highlights that these services vary in public bucket handling and IAM capabilities, with some lacking public-access controls entirely, and notes that credentials for these services are harder for tools like GitHub to detect. Wiz principal cloud security researcher Scott Piper warns that organizations cannot rely on AWS security assumptions when using S3 clones.", "body_md": "Security researchers at Wiz recently [examined S3-compatible object storage services](https://www.wiz.io/blog/s3-clones-in-the-neoclouds) across six popular neoclouds, revealing significant security gaps compared to Amazon S3. While S3 has become the de facto standard for object storage, most services lack several of AWS's security protections.\n\nThe report compares the security capabilities of managed services offered by [Nebius](https://docs.nebius.com/object-storage/interfaces/s3-api-compatibility), [Crusoe](https://support.crusoecloud.com/hc/en-us/articles/49200071604635-How-To-Use-Crusoe-Object-Storage-S3-Compatible-API), [Vultr](https://www.vultr.com/products/object-storage/), [Lambda Labs](https://docs.lambda.ai/public-cloud/s3-adapter-filesystems/), [Cloudflare R2](https://developers.cloudflare.com/r2/api/), and [DigitalOcean](https://docs.digitalocean.com/reference/api/spaces/) with Amazon S3. [Scott Piper](https://www.linkedin.com/in/scott-piper-security/), principal cloud security researcher at Wiz, shows that organizations using S3 clones cannot rely on AWS security assumptions and must account for reduced protections and limited least-privilege capabilities. Piper argues that S3 compatibility creates a dangerous false sense of portability:\n\nThere are nearly 300 APIs associated with AWS S3 and its related services (such as S3 tables, S3 vectors, S3 express, and more). All sorts of specialized functionality has been added to S3 over the more than 20 years of its existence, with trillions of objects and hundreds of exabytes of data stored within it. As you should expect, not all of that functionality has been replicated, and some of these S3 clones work in unexpected ways.\n\nAccording to the study, S3-compatible services vary significantly in how they handle public buckets, with Crusoe and Lambda Labs lacking public-access capabilities, while others provide fewer protections and controls than [AWS S3's Block Public Access](https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html). For example, Nebius, and Cloudflare R2 allow public buckets but not anonymous object listing, while DigitalOcean supports publicly listable buckets and Vultr supports both ACLs and bucket policies for public access.\n\nRegarding access keys, S3-compatible services often lack the structured access-key formats and secret-scanning support available for AWS ones, making credentials harder for both security teams and [tools such as GitHub to detect](https://docs.github.com/en/code-security/concepts/secret-security/secret-scanning). Piper explains:\n\nThere are other credentials detected by GitHub for DigitalOcean and Cloudflare through GitHub's secret scanning process, but not these. These credentials for the S3 compatible services are also not commonly found by other secret scanners. Part of the reason is that some of these do not have patterns that can be used.\n\nIAM capabilities and semantics differ considerably among S3-compatible implementations, something that has surfaced in the industry through multiple reported vulnerabilities, including [one in MinIO](https://advisory.eventussecurity.com/advisory/minio-object-storage-vulnerability-enables-unauthorized-privilege-escalation-attacks/) that enabled unauthorized privilege escalation and a [recent one in RustFS](https://app.opencve.io/cve/CVE-2026-49991) that breaks tenant isolation and authorization semantics.\n\n[Corey Quinn](https://www.linkedin.com/in/coquinn/), chief cloud economist at The Duckbill Group, summarizes it in his newsletter:\n\nEvery neocloud ships an S3-compatible endpoint, and your muscle memory follows you there whether the APIs behave or not. Wiz went poking through Nebius, Crusoe, Vultr and friends in this look at the S3 clones. On one, `delete-bucket-policy` deleted the entire bucket. Worth reading before you assume Block Public Access exists.\n\nAs S3-compatible services inherit [presigned URLs from the S3 API](https://docs.aws.amazon.com/AmazonS3/latest/userguide/using-presigned-url.html), all the clones support this capability and its associated security implications. Rishi Raj Singh, senior solutions engineer at Wiz, [writes](https://www.linkedin.com/posts/mrrishisingh_cloudsecurity-aws-s3-share-7490075633167990784-jtP1/) on LinkedIn:\n\nIf you are leveraging S3-compatible storage in neoclouds, ensure your team is explicitly auditing API behavior, verifying permissions models, and validating what happens when standard AWS tooling interacts with these endpoints.\n\nWiz’s review does not cover several other major S3-compatible implementations, including [Backblaze B2](https://www.backblaze.com/cloud-storage), [Wasabi](https://wasabi.com/), and [Google Cloud Storage](https://docs.cloud.google.com/storage/docs/interoperability). The [S3-compatible storage providers directory](https://blober.io/kb/articles/s3-compatible-storage-providers-complete-list/) currently lists more than 90 providers, while [Awesome Object Storage](https://github.com/mixpeek/awesome-object-storage) compares 21 providers across hyperscalers, alternatives, edge/CDN-native, self-hosted, and decentralized options.", "url": "https://wpnews.pro/news/s3-compatibility-doesn-t-guarantee-s3-level-security", "canonical_source": "https://www.infoq.com/news/2026/08/s3-clone-security/?utm_campaign=infoq_content&utm_source=infoq&utm_medium=feed&utm_term=global", "published_at": "2026-08-21 08:41:00+00:00", "updated_at": "2026-08-21 09:12:47.799754+00:00", "lang": "en", "topics": ["ai-infrastructure"], "entities": ["Wiz", "Amazon S3", "Nebius", "Crusoe", "Vultr", "Lambda Labs", "Cloudflare R2", "DigitalOcean"], "alternates": {"html": "https://wpnews.pro/news/s3-compatibility-doesn-t-guarantee-s3-level-security", "markdown": "https://wpnews.pro/news/s3-compatibility-doesn-t-guarantee-s3-level-security.md", "text": "https://wpnews.pro/news/s3-compatibility-doesn-t-guarantee-s3-level-security.txt", "jsonld": "https://wpnews.pro/news/s3-compatibility-doesn-t-guarantee-s3-level-security.jsonld"}}