flyinghaggis Posted November 23, 2018 Posted November 23, 2018 With the advent of GDPR we've been reviewing what's been shared and are finding that users are increasingly sharing files outside of the organisation from their own personal drives. The policy is that staff don't share to anyone with the link and always pick specific users. However, I'm not sure what the exact mechanism of authentication for this is when selecting users outside of the school/domain. It brought about a discussion over whether there was anyway this sharing could be compromised? My understanding was that in theory it requires an account so only the person who received the email will be able to view the document. However, we were wondering whether there was scope for this being abused if someone else managed to obtain this link? Does anyone have any links to exactly how the authentication mechanism works when sharing Google Apps drive links to specific email addresses outside of your own organisation? As a school do you generally allow staff to share files to others outside of you school/domain?
jthompson Posted November 23, 2018 Posted November 23, 2018 If it's the "Anyone with the link" option, then they don't need to authenticate at all (i.e. they don't need a Google account). The idea is that the URL used to access the item is sufficiently complex so as to protect it against anyone out there trying random URLs, bruteforcing to see what they can find, etc. The URL is basically its own password.
flyinghaggis Posted November 23, 2018 Author Posted November 23, 2018 If it's the "Anyone with the link" option, then they don't need to authenticate at all (i.e. they don't need a Google account). The idea is that the URL used to access the item is sufficiently complex so as to protect it against anyone out there trying random URLs, bruteforcing to see what they can find, etc. The URL is basically its own password. Yeah, that's why we've been asking staff not to use the "anyone with the link" method of sharing. It's more the "share this with specific people/email accounts" mechanism I was wondering about?
FN-GM Posted November 23, 2018 Posted November 23, 2018 It's more the "share this with specific people/email accounts" mechanism I was wondering about? For this to work the recipient must have a Google account. If they forward it onto another user and they try to access the content they are presented with a box to request access. It works the same as it would do sharing internally. We allow all sharing options as there are genuine requirements to have it. GDPR is more about policy and training than restrictions IMO.
flyinghaggis Posted November 23, 2018 Author Posted November 23, 2018 (edited) For this to work the recipient must have a Google account. If they forward it onto another user and they try to access the content they are presented with a box to request access. It works the same as it would do sharing internally. We allow all sharing options as there are genuine requirements to have it. GDPR is more about policy and training than restrictions IMO. That's what I thought but what's the mechanism if I share a document from our school to [email protected] (assuming Joe Bloggs doesn't have a Google Account)? Is it just a case of the first person to click the link (when there isn't an associated Google account) can create one with access to the shared material for that address. Other than the initial sign up email link being sent to that address is there anyway Google verifies the person opening that link is actually Joe Bloggs? I agree, we're not looking to restrict anything but I wondered what the mechanism was for securing external sharing from cloud systems like Office365 and Google Apps to external accounts? Edited November 23, 2018 by flyinghaggis
jthompson Posted November 23, 2018 Posted November 23, 2018 (edited) If you share with a specific email address, but that address is a non-Google account, they'll be emailed a link to view the item without needing to authenticate (as well as being invited to create a Google account in order to get any edit rights they may have been given). If they pass that link on to anyone else (e.g. by forwarding the email), that second person be able to view the item too, even if the file sharing level is set to 'Specific People'. You can manage that behaviour in Admin -> Apps -> G Suite -> Drive ->Sharing Settings -> Sharing options. If you have the "ON" radio option picked, you've got an option under there to "Require Google sign-in for external users to view file". However, if your intended recipient forwards the email on to someone else, that someone else can still gain access to the file, using whatever Google account they want. I don't believe Google will limit access in the way you want (i.e. it'll let in however many different Joe Publics use the link), but it's probably worth testing it. Edited November 23, 2018 by jthompson
elsiegee40 Posted November 23, 2018 Posted November 23, 2018 Moved to DP & Information Handling Forum as, while it's to do with a cloud service this topic belongs there
TwistedHelixis Posted November 23, 2018 Posted November 23, 2018 (edited) However, if your intended recipient forwards the email on to someone else, that someone else can still gain access to the file, using whatever Google account they want. But if I shared with [email protected] and they login, either using an existing gmail account or using another account does Google not setup a username / password against [email protected], so anyone else clicking on that link after would only be able to log in as [email protected]. The reason I think this is the case is, if I look at the share it has [email protected] listed as a user that has access, so anyone else would need to be accessing that file as [email protected] Not sure that made any sense Edited November 23, 2018 by TwistedHelixis
jthompson Posted November 23, 2018 Posted November 23, 2018 Yes, that makes sense. I'd advise testing it out: get [email protected] to create a new Google account off the back of the invitation email and open up the file as intended. Then forward the original invitation to [email protected] (from [email protected]) and see if Bob can still gain access with a different Google account. That will give you your answer.
flyinghaggis Posted November 23, 2018 Author Posted November 23, 2018 Yeah, that does seem to be how it works sharing to specific people in that it requires then to create an associated Google sign-in.
jthompson Posted November 23, 2018 Posted November 23, 2018 Yeah, that does seem to be how it works sharing to specific people in that it requires then to create an associated Google sign-in. Which then prevents anyone else reusing the invitation link? Would be interested to know the outcome if you're testing it.
flyinghaggis Posted November 23, 2018 Author Posted November 23, 2018 Which then prevents anyone else reusing the invitation link? Would be interested to know the outcome if you're testing it. Wont have time to test it today but I'd assume that if when a user signs up for a Google account it'll fire an email on first sign up to the address it's shared with in order to verify that you own that email account.
enjay Posted November 26, 2018 Posted November 26, 2018 There are other ways the data could be compromised: 1 - you share the data with [email protected] 2 - Joe right-clicks on the file/folder and selects "Add to my Drive" 3 - this adds the folder as an item in Joe's personal Google Drive 4 - Joe has Google Drive Sync installed, which downloads the shared folder onto his non-encrypted and shared home computer 1 - you share the data with [email protected] 2 - Joe right-clicks on the file/folder and selects "Add to my Drive" 3 - this adds the folder as an item in Joe's personal Google Drive 4 - Joe then adds that folder to another of his folders, which is shared with [email protected] 5 - Fred now has access to your documents, and you have no way of knowing this
jthompson Posted November 26, 2018 Posted November 26, 2018 There are other ways the data could be compromised: 1 - you share the data with [email protected] 2 - Joe right-clicks on the file/folder and selects "Add to my Drive" 3 - this adds the folder as an item in Joe's personal Google Drive 4 - Joe has Google Drive Sync installed, which downloads the shared folder onto his non-encrypted and shared home computer 1 - you share the data with [email protected] 2 - Joe right-clicks on the file/folder and selects "Add to my Drive" 3 - this adds the folder as an item in Joe's personal Google Drive 4 - Joe then adds that folder to another of his folders, which is shared with [email protected] 5 - Fred now has access to your documents, and you have no way of knowing this On this, provided the school retains ownership of the file(s), you'd be able to revoke those privileges somewhat. Obviously, once it's out there it's out there (strictly speaking), but I think the OP was getting at whether the activity log in Drive would show instances where different individuals were viewing the data (i.e. whether you'd be able to determine whether joe.bloggs had shared it onwards [using Drive sharing mechanisms] or not).
flyinghaggis Posted November 26, 2018 Author Posted November 26, 2018 (edited) There are other ways the data could be compromised: 1 - you share the data with [email protected] 2 - Joe right-clicks on the file/folder and selects "Add to my Drive" 3 - this adds the folder as an item in Joe's personal Google Drive 4 - Joe has Google Drive Sync installed, which downloads the shared folder onto his non-encrypted and shared home computer 1 - you share the data with [email protected] 2 - Joe right-clicks on the file/folder and selects "Add to my Drive" 3 - this adds the folder as an item in Joe's personal Google Drive 4 - Joe then adds that folder to another of his folders, which is shared with [email protected] 5 - Fred now has access to your documents, and you have no way of knowing this To be fair if you share documents with anyone there are a myriad of ways they could download and re-share those documents. The moral of the story is only to share documents/information you don't want redistributed with people who you trust. More worrying to me is the fact that staff seem to be frequently opting for the "anybody with the link" sharing option which means documents can be accessed effectively anonymously by anyone from anywhere. There are scenarios where this is required but most staff seem to be selecting this as the default whenever they share. In most cases selecting to share with specific groups of staff/pupils or everyone in the organisation would be more appropriate. We probably need to pass this up to the SLT/ICT teams for them to consider whether it can be addressed by more training or if we should be restricting this ability. Edited November 26, 2018 by flyinghaggis
atcoates Posted November 26, 2018 Posted November 26, 2018 Is the problem more because they are using drives not team drives?
enjay Posted November 26, 2018 Posted November 26, 2018 More worrying to me is the fact that staff seem to be frequently opting for the "anybody with the link" sharing option which means documents can be accessed effectively anonymously by anyone from anywhere. There are scenarios where this is required but most staff seem to be selecting this as the default whenever they share. In most cases selecting to share with specific groups of staff/pupils or everyone in the organisation would be more appropriate. I suspect this is happening when people paste document URLs into an email - we often do that, as you might be writing an email which says something like "please can you all have a look at this document" or whatever. When you do this, Google offers to share that document and when it does so, it selects "anyone with link" by default. You can change this so the default it selects is "recipients", can't remember how off the top of my head, but it wasn't complex.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now