AWSPlatform ChangesRetrospectives

S3 Block Public Access Launches (Nov 2018): The Feature That Should Have Existed Day One

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.

In November 2018, AWS launched S3 Block Public Access, a set of four settings that override bucket policies and access control lists to prevent public access — at the bucket level or across an entire AWS account.

What changed

Before Block Public Access, preventing public S3 buckets relied on every policy and ACL being written correctly. The new settings act as a safety net:

  • BlockPublicAcls: reject new public ACLs.
  • IgnorePublicAcls: ignore any existing public ACLs.
  • BlockPublicPolicy: reject bucket policies that grant public access.
  • RestrictPublicBuckets: restrict access to buckets with public policies to AWS services and authorized users only.

Applied at the account level, they protect every bucket in the account, including ones created later.

Why it mattered

After two years of high-profile S3 leaks, AWS gave customers a way to make public buckets impossible by default instead of relying on careful configuration. It was a shift from "secure if configured correctly" to "secure unless deliberately opened."

The follow-through

In April 2023, AWS made Block Public Access and disabled ACLs the default for all new buckets. With AWS Organizations and SCPs, organizations can also prevent anyone from turning the settings off.

In hindsight

Block Public Access is one of the clearest examples of a cloud provider fixing a systemic customer problem with a guard rail. It also shows the limits: defaults apply to new resources, and settings can still be changed by anyone with permission. Older accounts and buckets need deliberate attention — and in assessments today, accounts without account-level Block Public Access are still common.

s3 block public access2018

More on this story