[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Mail]  [Sign-in]  [Setup]  [Help]  [Register] 

"Leftists Make Desperate Attempt to Discredit Photo of Abrego Garcia's MS-13 Tattoos. Here Are Receipts"

"Trump Administration Freezes $2 Billion After Harvard Refuses to Meet Demands"on After Harvard Refuses to Meet Demands

"Doctors Committing Insurance Fraud to Conceal Trans Procedures, Texas Children’s Whistleblower Testifies"

"Left Using '8647' Symbol for Violence Against Trump, Musk"

KawasakiÂ’s new rideable robohorse is straight out of a sci-fi novel

"Trade should work for America, not rule it"

"The Stakes Couldn’t Be Higher in Wisconsin’s Supreme Court Race – What’s at Risk for the GOP"

"How Trump caught big-government fans in their own trap"

‘Are You Prepared for Violence?’

Greek Orthodox Archbishop gives President Trump a Cross, tells him "Make America Invincible"

"Trump signs executive order eliminating the Department of Education!!!"

"If AOC Is the Democratic Future, the Party Is Even Worse Off Than We Think"

"Ending EPA Overreach"

Closest Look Ever at How Pyramids Were Built

Moment the SpaceX crew Meets Stranded ISS Crew

The Exodus Pharaoh EXPLAINED!

Did the Israelites Really Cross the Red Sea? Stunning Evidence of the Location of Red Sea Crossing!

Are we experiencing a Triumph of Orthodoxy?

Judge Napolitano with Konstantin Malofeev (Moscow, Russia)

"Trump Administration Cancels Most USAID Programs, Folds Others into State Department"

Introducing Manus: The General AI Agent

"Chinese Spies in Our Military? Straight to Jail"

Any suggestion that the USA and NATO are "Helping" or have ever helped Ukraine needs to be shot down instantly

"Real problem with the Palestinians: Nobody wants them"

ACDC & The Rolling Stones - Rock Me Baby

Magnus Carlsen gives a London System lesson!

"The Democrats Are Suffering Through a Drought of Generational Talent"

7 Tactics Of The Enemy To Weaken Your Faith

Strange And Biblical Events Are Happening

Every year ... BusiesT casino gambling day -- in Las Vegas

Trump’s DOGE Plan Is Legally Untouchable—Elon Musk Holds the Scalpel

Palestinians: What do you think of the Trump plan for Gaza?

What Happens Inside Gaza’s Secret Tunnels? | Unpacked

Hamas Torture Bodycam Footage: "These Monsters Filmed it All" | IDF Warfighter Doron Keidar, Ep. 225

EXPOSED: The Dark Truth About the Hostages in Gaza

New Task Force Ready To Expose Dark Secrets

Egypt Amasses Forces on Israel’s Southern Border | World War 3 About to Start?

"Trump wants to dismantle the Education Department. Here’s how it would work"

test

"Federal Workers Concerned That Returning To Office Will Interfere With Them Not Working"

"Yes, the Democrats Have a Governing Problem – They Blame America First, Then Govern Accordingly"

"Trump and His New Frenemies, Abroad and at Home"

"The Left’s Sin Is of Omission and Lost Opportunity"

"How Trump’s team will break down the woke bureaucracy"

Pete Hegseth will be confirmed in a few minutes

"Greg Gutfeld Cooks Jessica Tarlov and Liberal Media in Brilliant Take on Trump's First Day"

"They Gave Trump the Center, and He Took It"

French doors

America THEN and NOW in 65 FASCINATING Photos

"CNN pundit Scott Jennings goes absolutely nuclear on Biden’s ‘farce’ of a farewell speech — and he’s not alone"


Status: Not Logged In; Sign In

Computers-Hacking
See other Computers-Hacking Articles

Title: Google Docs Design Flaw May Fool You Into Making Your Docs Editable by Anyone
Source: Wired
URL Source: http://blog.wired.com/business/2009/01/google-docs-des.html
Published: Jan 22, 2009
Author: Michael Calore
Post Date: 2009-01-22 15:39:01 by A K A Stone
Keywords: None
Views: 1707

If you're currently sharing spreadsheets, documents or presentations using Google Docs, go double-check the permissions settings of those shared docs right now.

Wired.com has discovered a design flaw in the web app's user interface that could lead users to mistakenly open up their docs to editing by anybody on the internet.

Funny thing is, we found out about it the hard way.

A co-worker of mine discovered Wednesday morning that the Wired Tech Layoff Tracker, a spreadsheet we're sharing with all of you using Google's free service, had been changed. The name of the reader who had edited the doc wasn't known to my co-worker, and he certainly hadn't knowingly given edit permissions to anyone outside Wired.com.

Thankfully, our hacker was a benevolent fellow who immediately notified us he had been able to edit our shared document. Thanks to him, we were able to correct the exploit before anyone else could fiddle with our spreadsheet.

The problem stems from a confusing bit of interface design in Google Docs.

Check out this screenshot:

Google_docs_example2

This is what you see when you choose to share a spreadsheet within Google Docs. (The red labels are my own). Shown is the Invite People tab, where you can add e-mail addresses of people you want to let view or edit your doc. You can also set permissions as you invite them, by clicking on the To Edit or To View radio buttons. I've labeled it section A.

At the bottom, in section B, are the Privacy settings, with three more radio buttons. The options are clear: You're choosing whether to let people edit or view the document without signing in, something that requires a Google account.

What's not clear is that in this instance, "people" in section B refers not to the people you've specifically invited in section A, but rather everyone on the internet.

Here's the next tab in the Sharing pane, People With Access:

Google_docs_example

Again, you have a list of permitted users and their preferences in section A, and an Ajax-powered menu in section B that lets you allow "people" to edit or view the doc with or without signing in.

As before, they way section B is worded, it's not clear "people" means everyone on the internet, not the list of people up in section A.

You can probably guess we had set our permissions to "Let people edit without signing in," which is what left us exposed. Why would we choose that setting? We simply wanted to lower the barrier of participation for everyone in the newsroom.

There are a few people working here (I won't name them) who don't trust Google and don't want a Google account, and therefore wouldn't add anything to our Layoff Tracker if we required them to sign in. Since we value their input, we left the option open, thinking we were only applying those privacy settings to our own approved invitees.

Some of you are probably reading this and thinking, "Duh!?" Maybe it's totally clear to you that the options in section A and section B aren't related, but it wasn't to us. Look at how those tabs are laid out and labeled, and it becomes easy to see how other users would make the same mistake we did. Even if it's a low number of users — say 10 percent — that's a big design flaw.

If you're currently sharing anything in Google Docs with the "Let people edit without signing in" option, be aware that your documents are about as secure as public wikis, especially if they're embedded in an HTML page or linked to from a public website. We recommend changing the settings on each shared document to "Always require sign-in." Also, update your notification settings to send you an e-mail whenever a document is edited by anyone.

I spoke with two representatives from the Google Apps team on the phone Wednesday afternoon, and they assured me Google has not heard of any instances where other users are getting tripped up by these privacy settings (That's not to say docs aren't being exposed, it just means nobody's reported untoward activity). The representatives did agree, however, that the interface was poorly worded and merits review, so they passed along our feedback to the rest of the Google Apps team.

Something else they stressed is that there's a big difference between using Google Docs to share your kids' soccer schedule and using it to share corporate data, which is why the company places more tight controls on its app offerings for small businesses. Google Apps Premiere Edition, a commercial cloud-based service ($50 per user per year) gives admins the ability to authorize users within a specific domain space — meaning users in your organization can be given permission to edit docs privately without logging in through a Google account.

The free version of Google Docs has been criticized for being lax around both security and legal issues, but as our little mishap proves, sometimes the weakest security link is the end user.

What do you think about Google Doc's security, especially when it comes to how "foolproof" the app is? What about collaborative, cloud-based services in general?

We'll update this post if Google makes any changes to this part of the app's interface.

Michael Calore">Click for Full Text!

Post Comment   Private Reply   Ignore Thread  


[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Mail]  [Sign-in]  [Setup]  [Help]  [Register] 

Please report web page problems, questions and comments to webmaster@libertysflame.com