Google Drive Found Leaking Private Data
31–40 of 78 posts
Re: Google Drive Found Leaking Private Data
#32Earlier quoted context omitted.
To clarify, I think what they mean is that it's possible that those old links have already been compromised, even though none of the documents (new or old) are vulnerable anymore. The bug has been patched so that any document with the "anyone with the link" permission will no longer leak its location in the referrer when someone clicks an HTTPS link in it. But it's possible that that happened in the past and the link…
That's still pretty bad, there could be millions of leaked document URL's in the logs of severs all over the internet and users haven't been notified. It looks like Microsoft Onedrive did a similar thing too: https://blog.onedrive.com/update-for-shared-links/ >"We chose not to disable all previously shared links, because the change only applies to a small fraction of shared files. If customers disable and then re-sha…
Re: Google Drive Found Leaking Private Data
#33Maybe I'm misunderstanding, but if the document in Google Drive is served over HTTPS, then the referrer when a user visits a linked site should only show the hostname (ie drive.google.com) not the full URL, right?
Re: Google Drive Found Leaking Private Data
#34I didn't think "Anyone with link..." setting promised any kind of security. Honestly, I don't think this was a 'security hole', more like a digital equivalent of a home owner hiding house keys under the carpet, hoping no one will look.
Re: Google Drive Found Leaking Private Data
#35This is news? Come on! You give anyone a link to your data and you expect security! Hello! If I gave folk a key to my house I doubt I'll have any my A/V equipment or computers when I come back after a long weekend. Why should I expect my data to be any safer!?
Yes. I expect security from my bank, from my insurance company, from state agencies, from my email provider, etc. I surely don't expect them to leak my data, and if they do, cause of a bug or incompetence, I want them to fix it.
And I want to be informed when they have breaches or fail to secure my data.
>Hello! If I gave folk a key to my house I doubt I'll have any my A/V equipment or computers when I come back after a long weekend.
People hire babysitters, cleaning stuff etc, give them the key to their house, and expect to have their A/V equipment when the come back.
If a cleaning person is reckless, and e.g leaves the door unlocked when he leaves, or a babysitter brings her pals over and have a party with my stuff, they get fired and/or sued, and people hire a more trusty person. Businesses that want to keep our private data should be kept to the same, or actually much higher, standards.
The "helloooo, is this news, of course it's unsafe, whaddaya expected" etc attitude doesn't help raise the bar on data safety.
Re: Google Drive Found Leaking Private Data
#36Earlier quoted context omitted.
If I know your bank's routing number (not a secret) and your account number, I can create a demand draft to take money out of your account. https://en.wikipedia.org/wiki/Demand_draft
What does that have to do with anything? If you issue fraudulent demand drafts, the bank will trace the destination account and send lawyers after you. If you trace referrers and open the origin URL, it's doubtful whether anyone will trace it or have legal recourse against you.
I'm aware of a story where a local credit union assigned account numbers strictly sequentially. A customer setting up direct-withdrawal typo'd their account number by omitting a digit, i.e. their acccount number was '12345' and they entered '1234'.
Since the numbers are sequential, '1234' happened to exist. For about a year, the company in question cheerfully direct-withdrew from the inappropriate account, and the original owner of '1234' never noticed, never complained, or had their complaints ignored. To my knowledge, the error was never rectified.
End of the day, direct-draft is a badly-architected system from a security standpoint.
Re: Google Drive Found Leaking Private Data
#37I'm glad Google fixed this, but if something is important you really shouldn't be securing it merely by giving it an obscure URL. Google Drive makes it very easy to say "only these named people" should have access, or "only people who have the link AND a google account for your company"
I'm not on my work computer, but I can't remember there ever being an option for only let people with a company google account see this. If that was the case, why wouldn't that just be on by default (which I would argue is everyone's expected behavior on corporate google drive).
Re: Google Drive Found Leaking Private Data
#38Earlier quoted context omitted.
Becomes less and less of an issue as sites switch to HTTPS though, right?
Referrers are still sent if you're clicking an https link on an https site, iirc.
Re: Google Drive Found Leaking Private Data
#39I didn't think "Anyone with link..." setting promised any kind of security. Honestly, I don't think this was a 'security hole', more like a digital equivalent of a home owner hiding house keys under the carpet, hoping no one will look.
That's not the issue. Let's say Alice shares a link to a Drive doc with Bob, https://drive/secretlink . If that document has an embedded link to Eve's website, http://some/thirdparty , and Bob clicks the link, then Eve (as the administrator of the third-party site) will see the HTTP Referer as https://drive/secretlink , and she will be able to access Alice's document.
However, the meta-point rishabhsagar touches on is that with an authentication-free access model, this is but one of possibly many potential failure modes. The risk surface is undefined size, but probably larger than your IT professionals are comfortable with.
Re: Google Drive Found Leaking Private Data
#40I didn't think "Anyone with link..." setting promised any kind of security. Honestly, I don't think this was a 'security hole', more like a digital equivalent of a home owner hiding house keys under the carpet, hoping no one will look.
Doesn't Google already have the right to parse your documents in Drive to show you ads?
They just recently pledged to stop parsing the paid Google Apps for Business emails to build ad preferences to show on other Google properties like YouTube.
I wonder if they're already scanning documents, and if we'd even know unless they were forced to stop making misleading statements acknowledge it in a court case like in the lawsuit over ad profiling students email in Google Apps for Education.
Not to mention that Schidmt or Nadella could have read your email or seen your company docs this morning and traded stocks based on them and Google/Microsoft are not even legally obliged to inform you that it happened.