[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Mail]  [Sign-in]  [Setup]  [Help]  [Register] 

"Why the DemocRATZ Activist Class Couldn’t Celebrate the Cease-Fire They Demanded"

Antifa Calls for CIVIL WAR!

British Police Make an Arrest...of a White Child Fishing in the Thames

"Sanctuary" Horde ASSAULTS Chicago... ELITE Marines SMASH Illegals Without Mercy

Trump hosts roundtable on ANTIFA

What's happening in Britain. Is happening in Ireland. The whole of Western Europe.

"The One About the Illegal Immigrant School Superintendent"

CouldnÂ’t believe he let me pet him at the end (Rhino)

Cops Go HANDS ON For Speaking At Meeting!

POWERFUL: Charlie Kirk's final speech delivered in South Korea 9/6/25

2026 in Bible Prophecy

2.4 Billion exposed to excessive heat

🔴 LIVE CHICAGO PORTLAND ICE IMMIGRATION DETENTION CENTER 24/7 PROTEST 9/28/2025

Young Conservative Proves Leftist Protesters Wrong

England is on the Brink of Civil War!

Charlie Kirk Shocks Florida State University With The TRUTH

IRL Confronting Protesters Outside UN Trump Meeting

The UK Revolution Has Started... Brit's Want Their Country Back

Inside Paris Dangerous ANTIFA Riots

Rioters STORM Chicago ICE HQ... "Deportation Unit" SCRAPES Invaders Off The Sidewalk

She Decoded A Specific Part In The Bible

Muslim College Student DUMBFOUNDED as Charlie Kirk Lists The Facts About Hamas

Charlie Kirk EVISCERATES Black Students After They OPENLY Support “Anti-White Racism” HEATED DEBATE

"Trump Rips U.N. as Useless During General Assembly Address: ‘Empty Words’"

Charlie Kirk VS the Wokies at University of Tennessee

Charlie Kirk Takes on 3 Professors & a Teacher

British leftist student tells Charlie Kirk facts are unfair

The 2 Billion View Video: Charlie Kirk's Most Viewed Clips of 2024

Antifa is now officially a terrorist organization.

The Greatness of Charlie Kirk: An Eyewitness Account of His Life and Martyrdom

Charlie Kirk Takes on Army of Libs at California's UCR

DR. ALVEDA KING: REST IN PEACE CHARLIE KIRK

Steven Bonnell wants to murder Americans he disagrees with

What the fagots LGBTQ really means

I watched Charlie Kirk get assassinated. This is my experience.

Elon Musk Delivers Stunning Remarks At Historic UK March (Tommy Robinson)

"Transcript: Mrs. Erika Kirk Delivers Public Address: ‘His Movement Will Go On’"

"Victor Davis Hanson to Newsmax: Kirk Slaying Crosses Rubicon"

Rest In Peace Charlie Kirk

Charlotte train murder: Graphic video captures random fatal stabbing of young Ukrainian refugee

Berlin in July 1945 - Probably the best restored film material you'll watch from that time!

Ok this is Funny

Walking Through 1980s Los Angeles: The City That Reinvented Cool

THE ZOMBIES OF AMERICA

THE OLDEST PHOTOS OF NEW YORK YOU'VE NEVER SEEN

John Rich – Calling Out P. Diddy, TVA Scandal, and Joel Osteen | SRS #232

Capablanca Teaches Us The ONLY Chess Opening You'll Ever Need

"How Bruce Springsteen Fooled America"

How ancient Rome was excavated in Italy in the 1920s. Unique rare videos and photos.

Reagan JOKE On The Homeless


Status: Not Logged In; Sign In

Computers-Hacking
See other Computers-Hacking Articles

Title: Google Docs Design Flaw May Fool You Into Making Your Docs Editable by Anyone
Source: Wired
URL Source: http://blog.wired.com/business/2009/01/google-docs-des.html
Published: Jan 22, 2009
Author: Michael Calore
Post Date: 2009-01-22 15:39:01 by A K A Stone
Keywords: None
Views: 1752

If you're currently sharing spreadsheets, documents or presentations using Google Docs, go double-check the permissions settings of those shared docs right now.

Wired.com has discovered a design flaw in the web app's user interface that could lead users to mistakenly open up their docs to editing by anybody on the internet.

Funny thing is, we found out about it the hard way.

A co-worker of mine discovered Wednesday morning that the Wired Tech Layoff Tracker, a spreadsheet we're sharing with all of you using Google's free service, had been changed. The name of the reader who had edited the doc wasn't known to my co-worker, and he certainly hadn't knowingly given edit permissions to anyone outside Wired.com.

Thankfully, our hacker was a benevolent fellow who immediately notified us he had been able to edit our shared document. Thanks to him, we were able to correct the exploit before anyone else could fiddle with our spreadsheet.

The problem stems from a confusing bit of interface design in Google Docs.

Check out this screenshot:

Google_docs_example2

This is what you see when you choose to share a spreadsheet within Google Docs. (The red labels are my own). Shown is the Invite People tab, where you can add e-mail addresses of people you want to let view or edit your doc. You can also set permissions as you invite them, by clicking on the To Edit or To View radio buttons. I've labeled it section A.

At the bottom, in section B, are the Privacy settings, with three more radio buttons. The options are clear: You're choosing whether to let people edit or view the document without signing in, something that requires a Google account.

What's not clear is that in this instance, "people" in section B refers not to the people you've specifically invited in section A, but rather everyone on the internet.

Here's the next tab in the Sharing pane, People With Access:

Google_docs_example

Again, you have a list of permitted users and their preferences in section A, and an Ajax-powered menu in section B that lets you allow "people" to edit or view the doc with or without signing in.

As before, they way section B is worded, it's not clear "people" means everyone on the internet, not the list of people up in section A.

You can probably guess we had set our permissions to "Let people edit without signing in," which is what left us exposed. Why would we choose that setting? We simply wanted to lower the barrier of participation for everyone in the newsroom.

There are a few people working here (I won't name them) who don't trust Google and don't want a Google account, and therefore wouldn't add anything to our Layoff Tracker if we required them to sign in. Since we value their input, we left the option open, thinking we were only applying those privacy settings to our own approved invitees.

Some of you are probably reading this and thinking, "Duh!?" Maybe it's totally clear to you that the options in section A and section B aren't related, but it wasn't to us. Look at how those tabs are laid out and labeled, and it becomes easy to see how other users would make the same mistake we did. Even if it's a low number of users — say 10 percent — that's a big design flaw.

If you're currently sharing anything in Google Docs with the "Let people edit without signing in" option, be aware that your documents are about as secure as public wikis, especially if they're embedded in an HTML page or linked to from a public website. We recommend changing the settings on each shared document to "Always require sign-in." Also, update your notification settings to send you an e-mail whenever a document is edited by anyone.

I spoke with two representatives from the Google Apps team on the phone Wednesday afternoon, and they assured me Google has not heard of any instances where other users are getting tripped up by these privacy settings (That's not to say docs aren't being exposed, it just means nobody's reported untoward activity). The representatives did agree, however, that the interface was poorly worded and merits review, so they passed along our feedback to the rest of the Google Apps team.

Something else they stressed is that there's a big difference between using Google Docs to share your kids' soccer schedule and using it to share corporate data, which is why the company places more tight controls on its app offerings for small businesses. Google Apps Premiere Edition, a commercial cloud-based service ($50 per user per year) gives admins the ability to authorize users within a specific domain space — meaning users in your organization can be given permission to edit docs privately without logging in through a Google account.

The free version of Google Docs has been criticized for being lax around both security and legal issues, but as our little mishap proves, sometimes the weakest security link is the end user.

What do you think about Google Doc's security, especially when it comes to how "foolproof" the app is? What about collaborative, cloud-based services in general?

We'll update this post if Google makes any changes to this part of the app's interface.

Michael Calore">Click for Full Text!

Post Comment   Private Reply   Ignore Thread  


[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Mail]  [Sign-in]  [Setup]  [Help]  [Register] 

Please report web page problems, questions and comments to webmaster@libertysflame.com