3 ms·
I was wondering this too. This isn't a direct answer to your question, but a quick search turned up this article for finding unsecured assets in a Google bucke
by leafmeal 6y ago
I was wondering this too.
This isn't a direct answer to your question, but a quick search turned up this article for finding unsecured assets in a Google bucket https://www.andreafortuna.org/2019/08/07/some-useful-tools-for-finding-unsecure-google-storage-buckets/ https://www.andreafortuna.org/2019/08/07/some-useful-tools-f...
- mtlynch 6y agoI'm currently mitigating those risks. The bucket name is not enumerable/guessable, even with brute force tools, and the filenames aren't predictable either. I have bucket enumeration set to forbidden.
- timc3 6y agoUse signed urls on the objects, and in your software for displaying the video create the correct download link on demand.
- mtlynch 6y agoRight, but that's likely multiple days of dev work. MediaGoblin's source code is a bit of a mess, and it's not GCS-aware at all, so it's non-trivial to implement support for GCS signed URLs and secure key management. What would be the value? If my family members send a link to someone else, that person will have the link forever? If the unauthorized person has a link to a video, they can simply download that video and keep it forever anyway. They can't retrieve other videos in the bucket unless they can correctly guess their (not very predictable) filenames.