Are my app's uploaded files public? (S3)

Also searched as: S3 bucket public access · S3 bucket public read prohibited · S3 bucket public access block · S3 bucket public vs private

Updated 3 October 2026

Short answer

New S3 buckets and files are private by default, but they can be opened with a bucket policy or file permissions, often to make images load easily during development. If yours was opened, anyone with a file's address can download it, including what your users uploaded. Turn on S3 Block Public Access, and serve private files through pre-signed links that expire.

What's the problem

Your app stores uploads (profile photos, documents, invoices, ID checks) in an S3 bucket. You're not sure whether those files can be opened by anyone with the link, or even listed by strangers.

Why it happens

  • Public was the quick fix. Images wouldn't load in the app, so the bucket was made public, and every private file with it.
  • Predictable addresses. File names built from user IDs or dates can be guessed, so "nobody knows the link" isn't protection.
  • One bucket for everything. Public assets (logos, product images) and private uploads share a bucket, so making one public made both public.

How to fix it

  1. Check the bucket's permissions in the AWS console: Block Public Access settings, the bucket policy, and any object access lists.
  2. Turn on Block Public Access for the bucket, and at account level if nothing should ever be public.
  3. Split public from private. Put genuinely public assets in their own bucket, or behind a CDN, and keep user uploads private.
  4. Serve private files with pre-signed URLs. Your server checks the user is allowed to see the file, then generates a link that works for a few minutes.
  5. Check what was exposed. If server access logging was on, look for downloads you don't recognise. If personal documents were public, see do I have to report a data breach.

When to call Preventionlabs

If switching on Block Public Access doesn't break anything, you're done. Call us when it does break things, because the app was built around public file links, or when nobody knows what's stored where. Data exposure and access control are on the MVP-level protection checklist in every resurrection, checked by trying to reach files you shouldn't, then fixed.

Submit your project for a free assessment

Free assessment. $10,000 AUD flat to get it live, only if we take it on and you go ahead.

Sources

  1. Amazon Web Services: Blocking public access to your Amazon S3 storagecloud platform docsBy default, new buckets, access points, and objects don't allow public access. However, users can modify bucket policies, access point policies, or object permissions to allow public access.
  2. Amazon Web Services: Blocking public access to your Amazon S3 storagecloud platform docsS3 Block Public Access settings override these policies and permissions so that you can limit public access to these resources.
  3. Amazon Web Services: Sharing objects with presigned URLscloud platform docsA presigned URL uses security credentials to grant time-limited permission to download objects.
← All of Is it safe?