3 ms·
To clarify, I think what they mean is that it's possible that those old links have already been compromised, even though none of the documents (new or old) are
by timothya 12y ago
To clarify, I think what they mean is that it's possible that those old links have already been compromised, even though none of the documents (new or old) are vulnerable anymore.
The bug has been patched so that any document with the "anyone with the link" permission will no longer leak its location in the referrer when someone clicks an HTTPS link in it. But it's possible that that happened in the past and the link was already leaked (and unfortunately, they can't exactly fix that). So if you have an old document, it's not vulnerable anymore, but it may at one time have been vulnerable so you might want to update it to have a new link (following the instructions in the Google blog post).
- lazersharks29 12y agoThat's still pretty bad, there could be millions of leaked document URL's in the logs of severs all over the internet and users haven't been notified. It looks like Microsoft Onedrive did a similar thing too: https://blog.onedrive.com/update-for-shared-links/ https://blog.onedrive.com/update-for-shared-links/ >"We chose not to disable all previously shared links, because the change only applies to a small fraction of shared files. If customers disable and then re-share a document, this will prevent further access to a document that might have been accessed."
- unreal37 12y agoHighly doubt it's millions. You have to upload a non-native format into Drive, modify the default security settings, and be linking to another HTTPS site and someone has to follow that link. AND the information in the original document has to be sensitive. The odds of that are very, very low.
- deleted 12y ago[deleted]
- f- 12y agoI helped draft the original blog post :-) To clarify a bit more and help folks evaluate their individual risk, it's worth noting that the impact is limited to a fairly specific scenario. In essence, you needed to have a non-native document format uploaded to Drive without converting it (PDF is a good example); explicitly share this document with others using a particular setting ("anyone with the link"); and then preview it in the web UI and follow an outgoing HTTPS link (HTTP wouldn't be a problem).