Jump to content

Recommended Posts

Posted

With the advent of GDPR we've been reviewing what's been shared and are finding that users are increasingly sharing files outside of the organisation from their own personal drives. The policy is that staff don't share to anyone with the link and always pick specific users.

 

However, I'm not sure what the exact mechanism of authentication for this is when selecting users outside of the school/domain. It brought about a discussion over whether there was anyway this sharing could be compromised? My understanding was that in theory it requires an account so only the person who received the email will be able to view the document. However, we were wondering whether there was scope for this being abused if someone else managed to obtain this link?

 

Does anyone have any links to exactly how the authentication mechanism works when sharing Google Apps drive links to specific email addresses outside of your own organisation?

 

As a school do you generally allow staff to share files to others outside of you school/domain?

Posted
If it's the "Anyone with the link" option, then they don't need to authenticate at all (i.e. they don't need a Google account). The idea is that the URL used to access the item is sufficiently complex so as to protect it against anyone out there trying random URLs, bruteforcing to see what they can find, etc. The URL is basically its own password.
Posted
If it's the "Anyone with the link" option, then they don't need to authenticate at all (i.e. they don't need a Google account). The idea is that the URL used to access the item is sufficiently complex so as to protect it against anyone out there trying random URLs, bruteforcing to see what they can find, etc. The URL is basically its own password.

 

Yeah, that's why we've been asking staff not to use the "anyone with the link" method of sharing.

 

It's more the "share this with specific people/email accounts" mechanism I was wondering about?

Posted
It's more the "share this with specific people/email accounts" mechanism I was wondering about?

 

For this to work the recipient must have a Google account. If they forward it onto another user and they try to access the content they are presented with a box to request access.

 

It works the same as it would do sharing internally.

 

We allow all sharing options as there are genuine requirements to have it. GDPR is more about policy and training than restrictions IMO.

Posted (edited)
For this to work the recipient must have a Google account. If they forward it onto another user and they try to access the content they are presented with a box to request access.

 

It works the same as it would do sharing internally.

 

We allow all sharing options as there are genuine requirements to have it. GDPR is more about policy and training than restrictions IMO.

 

That's what I thought but what's the mechanism if I share a document from our school to [email protected] (assuming Joe Bloggs doesn't have a Google Account)? Is it just a case of the first person to click the link (when there isn't an associated Google account) can create one with access to the shared material for that address. Other than the initial sign up email link being sent to that address is there anyway Google verifies the person opening that link is actually Joe Bloggs?

 

I agree, we're not looking to restrict anything but I wondered what the mechanism was for securing external sharing from cloud systems like Office365 and Google Apps to external accounts?

Edited by flyinghaggis
Posted (edited)

If you share with a specific email address, but that address is a non-Google account, they'll be emailed a link to view the item without needing to authenticate (as well as being invited to create a Google account in order to get any edit rights they may have been given).

If they pass that link on to anyone else (e.g. by forwarding the email), that second person be able to view the item too, even if the file sharing level is set to 'Specific People'.

 

You can manage that behaviour in Admin -> Apps -> G Suite -> Drive ->Sharing Settings -> Sharing options. If you have the "ON" radio option picked, you've got an option under there to "Require Google sign-in for external users to view file". However, if your intended recipient forwards the email on to someone else, that someone else can still gain access to the file, using whatever Google account they want. I don't believe Google will limit access in the way you want (i.e. it'll let in however many different Joe Publics use the link), but it's probably worth testing it.

Edited by jthompson
Posted (edited)
However, if your intended recipient forwards the email on to someone else, that someone else can still gain access to the file, using whatever Google account they want.

 

But if I shared with [email protected] and they login, either using an existing gmail account or using another account does Google not setup a username / password against [email protected], so anyone else clicking on that link after would only be able to log in as [email protected].

 

The reason I think this is the case is, if I look at the share it has [email protected] listed as a user that has access, so anyone else would need to be accessing that file as [email protected]

 

Not sure that made any sense

Edited by TwistedHelixis
Posted
Yeah, that does seem to be how it works sharing to specific people in that it requires then to create an associated Google sign-in.

 

Which then prevents anyone else reusing the invitation link? Would be interested to know the outcome if you're testing it.

Posted
Which then prevents anyone else reusing the invitation link? Would be interested to know the outcome if you're testing it.

 

Wont have time to test it today but I'd assume that if when a user signs up for a Google account it'll fire an email on first sign up to the address it's shared with in order to verify that you own that email account.

Posted

There are other ways the data could be compromised:

 

1 - you share the data with [email protected]

2 - Joe right-clicks on the file/folder and selects "Add to my Drive"

3 - this adds the folder as an item in Joe's personal Google Drive

4 - Joe has Google Drive Sync installed, which downloads the shared folder onto his non-encrypted and shared home computer

 

1 - you share the data with [email protected]

2 - Joe right-clicks on the file/folder and selects "Add to my Drive"

3 - this adds the folder as an item in Joe's personal Google Drive

4 - Joe then adds that folder to another of his folders, which is shared with [email protected]

5 - Fred now has access to your documents, and you have no way of knowing this

Posted
There are other ways the data could be compromised:

 

1 - you share the data with [email protected]

2 - Joe right-clicks on the file/folder and selects "Add to my Drive"

3 - this adds the folder as an item in Joe's personal Google Drive

4 - Joe has Google Drive Sync installed, which downloads the shared folder onto his non-encrypted and shared home computer

 

1 - you share the data with [email protected]

2 - Joe right-clicks on the file/folder and selects "Add to my Drive"

3 - this adds the folder as an item in Joe's personal Google Drive

4 - Joe then adds that folder to another of his folders, which is shared with [email protected]

5 - Fred now has access to your documents, and you have no way of knowing this

 

On this, provided the school retains ownership of the file(s), you'd be able to revoke those privileges somewhat. Obviously, once it's out there it's out there (strictly speaking), but I think the OP was getting at whether the activity log in Drive would show instances where different individuals were viewing the data (i.e. whether you'd be able to determine whether joe.bloggs had shared it onwards [using Drive sharing mechanisms] or not).

Posted (edited)
There are other ways the data could be compromised:

 

1 - you share the data with [email protected]

2 - Joe right-clicks on the file/folder and selects "Add to my Drive"

3 - this adds the folder as an item in Joe's personal Google Drive

4 - Joe has Google Drive Sync installed, which downloads the shared folder onto his non-encrypted and shared home computer

 

1 - you share the data with [email protected]

2 - Joe right-clicks on the file/folder and selects "Add to my Drive"

3 - this adds the folder as an item in Joe's personal Google Drive

4 - Joe then adds that folder to another of his folders, which is shared with [email protected]

5 - Fred now has access to your documents, and you have no way of knowing this

 

To be fair if you share documents with anyone there are a myriad of ways they could download and re-share those documents. The moral of the story is only to share documents/information you don't want redistributed with people who you trust.

 

More worrying to me is the fact that staff seem to be frequently opting for the "anybody with the link" sharing option which means documents can be accessed effectively anonymously by anyone from anywhere. There are scenarios where this is required but most staff seem to be selecting this as the default whenever they share. In most cases selecting to share with specific groups of staff/pupils or everyone in the organisation would be more appropriate.

 

We probably need to pass this up to the SLT/ICT teams for them to consider whether it can be addressed by more training or if we should be restricting this ability.

Edited by flyinghaggis
Posted
More worrying to me is the fact that staff seem to be frequently opting for the "anybody with the link" sharing option which means documents can be accessed effectively anonymously by anyone from anywhere. There are scenarios where this is required but most staff seem to be selecting this as the default whenever they share. In most cases selecting to share with specific groups of staff/pupils or everyone in the organisation would be more appropriate.

 

I suspect this is happening when people paste document URLs into an email - we often do that, as you might be writing an email which says something like "please can you all have a look at this document" or whatever. When you do this, Google offers to share that document and when it does so, it selects "anyone with link" by default. You can change this so the default it selects is "recipients", can't remember how off the top of my head, but it wasn't complex.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...