I have raised this issue on github:
https://github.com/W3EDGE/w3-total-cache/issues/461
And I will submit a PR very soon.
Yeah it does help, but there’s no reason for the objects to be public if they’re being served through CloudFront. I’ve had a look at the code and its because the S3 engine forces the ‘public-read’ ACL on every object it uploads. I’ll raise a bug on github and submit a PR.