Public storage

Object storage becomes public when a policy allows it, and the policies are easy to widen and easy to misread.

The long history of exposed buckets is almost entirely this: no attacker, no vulnerability, just a permission broader than intended and a URL anybody can request. Providers have added guardrails precisely because the failure was so consistent, and the setting can still be overridden.

Checked against the primary source.

More on Cloud security