Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For all intents and purposes, a signed, non-expiring S3 request is a public link, isn't it? Anybody can access it in perpetuity just by following the link. The only difference is that the signed request is unpredictable and public links are probably predictable by default. So just include a UUID in your key and you are set.


The public link can be just as unpredictable.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: