AWSPlatform ChangesRetrospectives

AWS Encrypts All New S3 Objects by Default (Jan 2023)

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from January 2023, written in 2026 with the benefit of hindsight.

On January 5, 2023, AWS began automatically applying server-side encryption with Amazon S3 managed keys (SSE-S3) to all new objects uploaded to S3, at no additional cost and with no performance impact.

What changed

Previously, encryption at rest for S3 was optional — customers enabled default bucket encryption themselves. After the change:

  • Every new object in every bucket was encrypted with SSE-S3 unless another encryption method was specified.
  • Existing unencrypted objects remained unencrypted until rewritten.
  • Customers could still choose SSE-KMS (AWS KMS keys) or later DSSE-KMS (dual-layer encryption).

Why it mattered

Encryption at rest was a common compliance requirement and audit finding. Making it default removed a configuration step and a whole class of findings.

What it didn't do

Default encryption with S3-managed keys protects against physical access to storage media. It does not protect against someone with valid AWS permissions reading data — S3 decrypts transparently for authorized requests. A misconfigured bucket policy that allows public access still exposes data, encrypted or not.

For stronger control, SSE-KMS with customer-managed keys adds a second permission layer: users need both S3 permissions and KMS key permissions, and key usage is logged in CloudTrail.

In hindsight

Default encryption is a good example of a security baseline becoming invisible. The remaining work — deciding which data needs KMS keys, key policies and separation of duties — is where real access control happens.

s3 default encryption2023

More on this story