# S3 Backup ... sospecha de problema de acceso

**URL:** https://meta.discourse.org/t/s3-backup-suspect-access-issue/97134
**Category:** Support
**Created:** [13 Septiembre, 2018 17:52 UTC](https://meta.discourse.org/t/s3-backup-suspect-access-issue/97134 "2018-09-13T17:52:54Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![merefield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/merefield/32/176214_2.png) [@merefield](https://meta.discourse.org/u/merefield)
#### Post date: [13 Septiembre, 2018 18:01 UTC](https://meta.discourse.org/t/s3-backup-suspect-access-issue/97134/2 "2018-09-13T18:01:52Z")

</div>

Going to try an element of this policy here:

> [@IAM and bucket policy for S3 access](https://meta.discourse.org/t/iam-and-bucket-policy-for-s3-access/87222):
>
> I noticed that all of the tutorials i found for Discourse S3 access granted the user absolute authority over the bucket – they allow ‘s3:\*’ authority. This is an extremely unwise policy, since it allows significantly more control over the bucket than is reasonable. Should you be using S3 for Discourse backup storage, a rampaging attacker would be able to delete your bucket and your backups on the way out. There are two ways to combat this: One, a tighter policy… { "Version": "2012-10-17",…

---

_[View the full topic](https://meta.discourse.org/t/s3-backup-suspect-access-issue/97134)._
