3 ms·
Dropbox also does that. You can potentially host your website within your 'Public' Dropbox folder. I'm sure Google is not using http://googledrive.com/ http://
by adhipg 14y ago
Dropbox also does that. You can potentially host your website within your 'Public' Dropbox folder.
I'm sure Google is not using http://googledrive.com/ http://googledrive.com/ for anything that's user-identifiable.
The only harm that I think can happen with JS is you being able to access/set any cookies/storage that are set by another 'public' site hosted on Google Drive that you've accessed earlier.
- mchanson 14y agoDropbox shuts links down if you get any significant traffic.
- businessleads 14y agoThat doesn't sound very fun...
- ollieglass 14y agoReally? Could you give more detail - at what level of traffic do they shut down links?
- mchanson 14y agohttps://www.dropbox.com/help/45/en https://www.dropbox.com/help/45/en Looks like 20GB (free) or 200GB (paid) per day.
- jjsz 14y agoThat's PER link, so you can drop it in another folder, change the link, and maybe it refreshes since it's a different link? Can someone from Dropbox confirm this?
- qued 14y agoSeems like more than enough for simple sites shared with a bunch of people you know. That is about 600 GBs of bandwidth a month, for free. If you need more bandwidth, you would probably be looking at any of the other innumerable hosting solutions available on the web.
- eli 14y agoNote that Dropbox discourages the use of Public folders. New accounts don't get one unless you know to request it.
- FooBarWidget 14y ago> I'm sure Google is not using http://googledrive.com/ http://googledrive.com/ for anything that's user-identifiable. Look at the screenshot in the article. It is in fact using https://googledrive.com/ https://googledrive.com/
- IWentToTheWoods 14y agoYes, it uses googledrive.com, but not for anything user-identifiable. The threat is that a user logs in to googledrive.com and receives an authentication cookie tied to their Google account. Later, they view a malicious user page at googledrive.com/host/someevilpage, and a script on that page reads the authentication cookie and sends it to the attacker, who can now log in to googledrive.com as the victim. That doesn't happen here because you don't actually log in to googledrive.com. The worst a malicious script could do is harvest data set by other scripts, and that's a drastically smaller (although still present) threat.
- rukshn 14y agoyou don't need to login in to have session cookeis isn't it? The google session cookies work in all google services a like isn't it?