logoalt Hacker News

echoangletoday at 2:42 PM1 replyview on HN

I think you can put malicious data in the bucket and „impersonate“ the deleted bucket, so old code referencing the bucket uses your data instead of throwing an error (?).


Replies

returningfory2today at 3:26 PM

Or old code referencing the bucket _writes_ data to it, and the attacker can now read it.