rotadvantage.blogg.se

How to share my google drive with someone
How to share my google drive with someone






how to share my google drive with someone

Ok I have some additional information, and now understand better what is happening. If, in both cases, anybody with the link can view the file, then there is no difference and the file is not actually restricted. If it is functioning the way it is supposed to, what is the difference then between Restricted and Non-Restircted sharing? this forces them to login so they can access it the file. The whole point of restricted sharing is that the person MUST have a google account in order to view the file. I believe this has to work like that if you share with users (e-mail addresses) who don't have a Google account, as there's no identifier on our end that you can grant authority to.

how to share my google drive with someone how to share my google drive with someone

Only forward it to people you trust."Īs far as a detailed attack scenario goes, all I can tell you is that email is generally considered an insecure method of transmitting data, and if there is a link in my email that "grants access to this item without logging in" then my file is no longer Restricted to the users that have been added if my email gets hijacked or intercepted. This makes "Restricted" and "Anyone with the link" exactly the same thing, because even though I have restricted it to certain users, there is a link available that anyone can use to access it.Ī file set to Restricted should NOT be creating a link in an email that says "This email grants access to this item without logging in. If a link is generated that allows anybody to click on it and then view the file, then that completely bypasses the "restricted" feature altogther. If I RESTRICT a file to specific users, then only those specific users should be able to access the file after they have logged in. That said – if you think we misunderstood your report, and you see a well-defined security risk, please provide a detailedĪttack scenario where you demonstrate how this issue could be exploited to attack other users or Google. Hi! Although it may come as a surprise, this is actually working as intended. The employees email is hijacked and the hacker with the link can now view the document even though they have not logged in. I set a senesitive/private document to RESTRICTED and share with an employee. Anybody with the link can now view the document without logging in, even though it is set to RESTRICTED.In the email it says "This email grants access to this item without logging in.User receives an email that Document was shared with them.Under sharing, set the file to RESTRICTED.Summary: Sharing a Restricted file sends email to added user with link accessible by anyone Note Google's response that this is apparently working as intended. If the Public Link option and the Restricted option both give anybody access to the file, then what is the difference? Per issue tracker, Google seems to think this is okay.Īm I missing something here, or misunderstanding how this is supposed to work?ĮDIT: I have more details on the issue and it is better described as this: Restricted files that have been shared with a non-Google email incorrectly still show their status as Restricted, when in reality they are accessible by Anyone with the link.ĮDIT: The tracker link is not accessible to everybody, so I am reproducing the thread here. However, Google seems to think that anybody with the link should be able to access the file, whether they are logged in or not.

how to share my google drive with someone

So it seems to me that when I share a Google Drive file using the Restricted option, that only the person I shared it with should be able to access it.








How to share my google drive with someone