It requires ``` { "Effect": "Allow", "Principal": "*", "Action": "s3:ListAllMyBuckets", "Resource": "arn:aws:s3:::*" } ``` which is cancer; we should prolly just check for each bucket individually