AWS Makes S3 Buckets Safer by Disabling Customer-Managed Encryption by Default
The announcement introduces a new default security setting for Amazon S3 that disables server-side encryption with customer-provided keys (SSE-C) on all new buckets starting in April 2026. Existing buckets without SSE-C usage will also have it disabled automatically. This change pushes users toward AWS-managed encryption options like SSE-S3 or SSE-KMS, which are easier to audit and integrate. While SSE-C can still be enabled manually, the shift reduces risk from mismanaged keys and aligns S3 defaults with more secure, standardized encryption practices.
https://aws.amazon.com/about-aws/whats-new/2026/04/s3-default-bucket-security-setting
Comments
Post a Comment