S3 Block Public Access Launches (Nov 2018): The Feature That Should Have Existed Day One
Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.
In November 2018, AWS launched S3 Block Public Access, a set of four settings that override bucket policies and access control lists to prevent public access — at the bucket level or across an entire AWS account.
What changed
Before Block Public Access, preventing public S3 buckets relied on every policy and ACL being written correctly. The new settings act as a safety net:
- BlockPublicAcls: reject new public ACLs.
- IgnorePublicAcls: ignore any existing public ACLs.
- BlockPublicPolicy: reject bucket policies that grant public access.
- RestrictPublicBuckets: restrict access to buckets with public policies to AWS services and authorized users only.
Applied at the account level, they protect every bucket in the account, including ones created later.
Why it mattered
After two years of high-profile S3 leaks, AWS gave customers a way to make public buckets impossible by default instead of relying on careful configuration. It was a shift from "secure if configured correctly" to "secure unless deliberately opened."
The follow-through
In April 2023, AWS made Block Public Access and disabled ACLs the default for all new buckets. With AWS Organizations and SCPs, organizations can also prevent anyone from turning the settings off.
In hindsight
Block Public Access is one of the clearest examples of a cloud provider fixing a systemic customer problem with a guard rail. It also shows the limits: defaults apply to new resources, and settings can still be changed by anyone with permission. Older accounts and buckets need deliberate attention — and in assessments today, accounts without account-level Block Public Access are still common.
- How to Enforce S3 Block Public Access at the AWS Organization Level How-To & Hardening
- S3 Public Access Audit Checklist How-To & Hardening
- CIO Brief: One Setting That Prevents the Most Common Cloud Breach CIO Briefings