S3 Compatibility

S3 Compatible Doesn't Mean Secure: What Neoclouds Miss

S3 compatibility has become the default promise for object storage, but as Wiz's research shows, that promise stops short of security.

3 min readInfoQ
S3 Compatible Doesn't Mean Secure: What Neoclouds Miss

The Wiz research lands at an uncomfortable intersection: S3 compatibility has become the default promise of every object storage service, yet the security that underpins S3's reputation is not part of that promise. Across six popular neoclouds, the report found meaningful gaps between what Amazon S3 offers by default and what these compatible services actually deliver. That gap is not a small print footnote. It is the difference between assuming your data is protected and verifying that it is.

For readers who have spent years treating S3 as the baseline for cloud storage, this is the moment to stop treating compatibility as equivalence. The same way AWS has been pushing complexity higher up the stack, as seen in its recent work on Scale AWS Server Deployments Effortlessly with Stateless Model Context Protocol, the security burden is shifting too. But here, the shift is not about simplifying operations. It is about recognizing that the API contract only covers how you talk to the service, not what the service protects on your behalf. Encryption at rest, access policies, bucket-level controls, and logging mechanisms are often implemented differently, and sometimes not at all, even when the S3 API responds identically.

This is not an argument against neoclouds. The momentum behind these providers is real, and the innovation they bring to data management is worth exploring. But the Wiz findings should temper the enthusiasm with a hard question: what does your security model actually assume? If you have adopted a neocloud because it feels more modern or more flexible, the same way Cloudflare's Blog Finds Performance Gains with EmDash, Its New CMS shows how a fresh tool can beat a legacy one on specific metrics, you still need to verify that the security baseline matches the workload's actual risk. Performance and convenience do not substitute for access control.

What we would tell a reader who asks for advice is straightforward: audit before you adopt. Do not assume that because your client library works unchanged, your security policies do too. Test the specific security features you rely on, not the ones the provider advertises. Check whether bucket policies support the same conditions, whether versioning behaves the same under attack, whether logging captures the events you need. The practical takeaway is sharp: S3 compatibility guarantees your code runs, but it does not guarantee your data stays safe. That responsibility still sits with you, and the Wiz research is a reminder that the cheapest moment to discover a security gap is before you migrate, not after.

The open question now is whether the neoclouds will treat this as a competitive weakness and close the gap, or as a cost center and leave it. For the teams evaluating these services today, the answer decides whether the next few years bring smoother operations or a painful security wake-up call.

From InfoQ

Security researchers at Wiz recently examined S3-compatible object storage services across six popular neoclouds, revealing significant security gaps compared to Amazon S3. While S3 has become the de facto standard for object storage, most services lack several of AWS's security protections.

Read the original at InfoQ