What team did you report this issue to? I think this is more about the Slack Google Drive plugin's behavior than Google Docs per se. If someone with permission to view the doc takes a screenshot of the first page of the doc and sends that to you, there's nothing really that Google Docs can do to stop that. That's analagous to what's happening here. The Google Docs Slack integration is what's sharing the preview image…
Google marked this vulnerability as "Won't Fix" but I disagree. Care to comment?
21–26 of 26 posts
Re: Google marked this vulnerability as "Won't Fix" but I disagree. Care to comment?
#22What team did you report this issue to? I think this is more about the Slack Google Drive plugin's behavior than Google Docs per se. If someone with permission to view the doc takes a screenshot of the first page of the doc and sends that to you, there's nothing really that Google Docs can do to stop that. That's analagous to what's happening here. The Google Docs Slack integration is what's sharing the preview image…
I'm not sure why the plugin has (or needs to have) access to the private doc in the first place. I would expect a communications channel to communicate my link, not act as a third person with priviledged credentials.
It is not intuitive if you are not used to how security really works, which is that permissions are granted to masks that you wear, not to any real person. When you give slack permissions to use the drive integration, you are giving them a copy of your mask, and they are you, even unexpectedly. You have a (subconscious) reflex to automatically create and share screenshots of documents that you link, that you have trained via slack's hook. Remove that integration, and everything works as expected.
Re: Google marked this vulnerability as "Won't Fix" but I disagree. Care to comment?
#23If I follow correctly yes this is an obvious vulnerability. Someone at Google made the wrong decision to not fix this years ago and keeps doubling down on that decision. If someone does a blog post like “Looking at the first page of 1 billion private Google Docs” they’ll fix it.
Re: Google marked this vulnerability as "Won't Fix" but I disagree. Care to comment?
#24Surely it is not just anyone that a link is shared with, but anyone with the link? It's link-bearer open access to a partial document (an entire page) an author marks as not having partial access. Circumvention of Google's authentication procedure. Is that understanding correct? If so, Google's seemingly OK with users believing something's secure, that isn't. And that could cause information leakage by Google's desig…
Isn't this just restating in an obscure and poorly worded fashion what the very clearly worded original post said?
> Is that understanding correct?
I must have phrased these 4 words poorly. I'll try harder next time.
Re: Google marked this vulnerability as "Won't Fix" but I disagree. Care to comment?
#25This looks like a security vulnerability to me. I pay for Google Drive, and I'm starting to distrust Google to maintain the safety of my data properly.
Re: Google marked this vulnerability as "Won't Fix" but I disagree. Care to comment?
#26And yeah, I think it's ridiculous.