As far as I’m aware, the Access Key ID is like a username, and without the Access Key Secret it’s useless?
Even if the associated user has full S3 permissions?
Is there anyway other than a 0day aws exploit that you can manage/delete everything without having the secret?