Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
World desk3 min

Is Amazon S3 Encrypted in Transit by Default?

S3’s default server-side encryption protects new objects at rest, not necessarily while data travels to or from the service. Require HTTPS separately with a bucket policy.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

No. Amazon S3 encrypts new object uploads at rest by default, but that does not mean requests and responses are protected in transit. To make a general-purpose bucket reject unencrypted HTTP requests, add a bucket policy that denies requests unless they use HTTPS. Check existing objects and test your applications before enforcing the policy.

What S3’s default encryption does—and does not do

Encryption at rest protects object data while it is stored. AWS says S3 encrypts objects before saving them to disks and decrypts them when they are downloaded. This is server-side encryption; it does not, by itself, require a client to connect over HTTPS. AWS: Protecting data with encryption

As an Amazon Associate I earn from qualifying purchases.

Since January 5, 2023, S3 has automatically applied SSE-S3 server-side encryption to new object uploads by default. AWS says this automatic default has no additional cost and no performance impact. AWS: Default encryption FAQ

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

S3 also offers SSE-KMS and DSSE-KMS for different key-management controls or dual-layer encryption. These are choices for encryption at rest, not substitutes for requiring encrypted transport. SSE-KMS and DSSE-KMS also involve AWS KMS permissions and request quotas. Review the current configuration and requirements in AWS’s default encryption documentation.

At rest versus in transit

Protection What it covers How it is controlled
At rest Object data stored by S3 Server-side encryption, such as SSE-S3, SSE-KMS, or DSSE-KMS
In transit Requests and responses moving between a client and S3 HTTPS/TLS for the connection; a bucket policy can deny requests that do not use secure transport

AWS accepts HTTP traffic to S3 in general. Its documentation recommends HTTPS/TLS to protect data as it travels between clients and S3. A bucket’s at-rest encryption setting should therefore not be treated as evidence that HTTP requests are blocked. AWS: Protecting data in transit with encryption

How to require HTTPS for a bucket

Use a bucket policy with an explicit Deny for requests where the aws:SecureTransport condition is false. The resource scope should include both the bucket ARN and its objects. Adapt AWS’s documented policy example to your bucket and review it before deployment:

Rank #2
Coaster Westpark 61-Inch 3-Piece 9-Shelf Bookcase Set, Black 802703-S3
  • Includes: Three (3) bookcases
  • Three-piece bookcase set functions as a wall unit, tower shelf, or freestanding storage system
  • Scratch-resistant laminate veneer finish over durable engineered wood frame
  • Open shelving offers accessible space for books, décor, and display items
  • Top drawers include secure locks to keep personal items and electronics protected
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "DenyInsecureTransport",
      "Effect": "Deny",
      "Principal": "*",
      "Action": "s3:*",
      "Resource": [
        "arn:aws:s3:::BUCKET_NAME",
        "arn:aws:s3:::BUCKET_NAME/*"
      ],
      "Condition": {
        "Bool": {
          "aws:SecureTransport": "false"
        }
      }
    }
  ]
}

Replace BUCKET_NAME with the bucket’s actual name. An explicit deny blocks insecure requests even if another policy would otherwise allow access. AWS provides the policy syntax and transport guidance in Protecting data in transit with encryption.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Require a minimum TLS version if needed

HTTPS-only enforcement and minimum protocol enforcement are distinct requirements. If your security standard specifies an approved minimum TLS version, use the documented s3:TlsVersion condition in a policy designed for that requirement. Set the version to your organization’s approved minimum rather than assuming one universal threshold. See AWS’s transport policy examples.

Test before enforcing the deny

Because the policy rejects non-TLS requests, first confirm that every intended access path works over HTTPS. Test application clients and SDKs, presigned URLs, scheduled jobs, and third-party integrations. Also review public and cross-account access patterns so the policy does not unintentionally break required behavior. AWS recommends allowing only encrypted HTTPS/TLS connections with aws:SecureTransport in S3 bucket policies. AWS: Security best practices for Amazon S3

For ongoing visibility, AWS recommends monitoring HTTP access attempts using CloudWatch alarms and CloudTrail TLS details. That helps identify attempted insecure access rather than relying only on the policy’s blocking effect. AWS: Security best practices for Amazon S3

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check existing objects and access controls separately

Changing a bucket’s default encryption configuration does not retroactively change encryption on objects that already exist. Review the objects themselves and AWS’s current remediation guidance for your workload before deciding whether existing data needs separate action. AWS: Configuring default encryption

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Encryption is only one part of S3 security. Bucket policies, identity permissions, and other access controls determine who can access data; neither at-rest encryption nor TLS alone prevents an authorized-but-overprivileged identity from reading it. For broader security guidance, see AWS Prescriptive Guidance: Amazon Simple Storage Service.

This guidance is for general-purpose S3 buckets. Directory buckets and specialized features may have separate behavior; check their dedicated AWS documentation before applying a general-purpose bucket policy.

Quick Recap

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.